Security and privacy

Built for sensitive unsupervised visit records

Visit Bridge uses role-based access, parent-track boundaries, tenant-aware database policies, audit logging, and operational release checks for organizations that manage child, family, court, attorney, and scheduling records.

Tenant isolation

Supabase Auth, company memberships, role checks, and row-level security policies isolate company data.

Audit trail

Sensitive actions write audit events through a database RPC that derives actor identity from the authenticated session.

Attachment handling

Generated plan records and supporting files are private, scoped, validated, and served only through controlled access paths.

Operational readiness

Release gates include linting, typechecking, unit tests, coverage, production builds, e2e smoke tests, and a health endpoint.

Buyer review packet

Privacy, retention, support access, backup, deployment, and incident response documents are maintained in the release packet and should be reviewed with counsel and customer stakeholders before processing real production records.

Need security context before onboarding?

Contact us to review controls with your stakeholders, or sign in if your organization already has access.