Security & trust
The most sensitive data a family will ever hand over.
Medical histories, legal agreements, payment schedules, and the identities of everyone involved in creating a child. Below is how it is held, who can reach it, and — the part most vendors leave out — what we deliberately refuse to do with it.
Encrypted in transit and at rest
TLS on every connection, encryption at rest on the database and on stored documents. No unencrypted copy of a medical record exists anywhere in the system.
Isolated per agency
Each agency’s data is separated at the database layer, not filtered in application code. A query written for one agency cannot reach another’s families.
Access by role, not by trust
A coordinator sees the cases they carry. A viewer cannot edit. An admin cannot silently read a portal conversation without it appearing in the trail.
Who can see what
Four audiences on one record, each seeing only their part.
A surrogate and an intended parent share a journey but not a view of it. The hard part of this product is not storing the data — it is making sure each person sees exactly their share of it, every time, without a coordinator having to think about it.
Visibility is set per document and per message, not per folder — so a medical record shared with a clinic does not become visible to everyone who can see the case.
The refusals
What we will not do with your data.
Most of a security page is a list of things a vendor has. This is the list of things we have decided against — which is usually the more useful one, because it is the part that cannot quietly change once you have signed.
We do not hold anyone’s money
Payments are tracked against milestones and never processed here. Escrow, transfers and card handling stay with the people already licensed and insured to do them. We are not in the flow of your clients’ funds.
We do not train models on your families
Your data is not used to train anything, ours or anyone else’s. A surrogacy journey is not training material, and no amount of product improvement would justify it.
We do not put our brand in front of your clients
The portals are yours end to end — your name, your address, your colours. Your clients never learn we exist, and we never contact them for any reason.
We do not sell, share, or analyse across agencies
No benchmarking product built from your book, no aggregate data sold onward, no “industry insights” assembled from other people’s families. Your data leaves your tenant only when you export it.
The audit trail
Every action, attributable.
Who did what, when, and what it changed — recorded on the case rather than reconstructed from memory afterwards. When a family, a lawyer or a regulator asks how a decision was reached, the answer is a record you can hand over, not an account of what someone remembers.
This matters most at exactly the moments it is hardest to reconstruct: a match that was declined, a clearance that expired, a payment that was queried.
Where we are still building
The part a security page usually hides.
We are a young platform. Some of what a large agency’s procurement team will ask for is in place, and some is not yet. You should hear which is which from us, now, rather than from a questionnaire in month three.
In place today
- Encryption in transit and at rest
- Tenant isolation at the database layer
- Role-based access and per-item visibility
- Append-only audit trail on every action
- A single, named hosting region
Not yet in place
- SOC 2 Type II — not yet certified; audit not yet begun
- Third-party penetration test — not yet commissioned
- Customer-managed encryption keys — planned for licence agreements
- HIPAA BAA — not yet offered; ask us and we will tell you where it stands
If your procurement process needs something not listed here, ask. We would rather tell you we do not have it yet than discover the gap together during an onboarding.
Send us your security questionnaire.
We will fill it in properly, mark honestly what we do not yet have, and tell you where the rest stands. No security theatre.