Security and data handling

A page you can forward to your funder.

Structural facts about how COMPASS handles client data, and a plain list of the things we do not claim. Short on purpose. A long security page usually means somebody is padding.

Who can see what

Access in COMPASS is granted capability by capability rather than by job title. There are more than 200 of them, and an organization sets its own combinations without asking us.

Capabilities, not rolesA bookkeeper can approve expenses without seeing pay rates. A volunteer coordinator can see schedules without seeing client records. Job titles in COMPASS are labels; the access sits on the capability.
42 CFR Part 2 recordsSubstance use records sit behind their own permission with explicit consent recording, separate from general client access, as the regulation requires.
Mental health recordsGated by a permission of their own, independent of whether someone can open the rest of the client record.
Break-glass, and it is recordedPrivacy restrictions can be overridden by a specifically permissioned user when circumstances demand it. The override is written down. That second half is the part that matters.
Two-factor authenticationStandards-based one-time passcodes with QR enrollment and backup codes, working with any authenticator app. An organization can require it for everyone.
Organizations are separatedSeparation between organizations is enforced at the database layer rather than in application code.

Nothing quietly disappears

Case notes and time entries are attested records. Somebody signed them, a funder may audit them, and payroll may depend on them. COMPASS treats them that way.

Edits create versionsSession logs, case notes and time entries are versioned. An edit writes a new version and preserves the original rather than overwriting it.
Deletions leave a markerA deleted record leaves a tombstone. You can tell that something was removed, and when, rather than finding a gap.
Editing a signed record clears the signatureChange a signed timesheet and the signature comes off. It has to be signed again. A signature in COMPASS always refers to what is actually in the record.
Separation of dutiesA form cannot be cosigned by the person who started it. Enforced by the system rather than by policy.
Audit trailSignificant actions are logged with the user, the timestamp and the detail. Exportable, and the retention period is yours to configure.

What we do not collect

No tracking in the appThe COMPASS application runs no analytics, no advertising and no tracking of any kind. Not a reduced amount. None.
This site is cookielessOur marketing site uses privacy-preserving analytics with no cookies, no client-side storage, no fingerprinting and no cross-site tracking.
No client data reaches our payment processorBilling carries your organization name, plan and identifier. Client records never touch it. That is a contractual constraint, not a setting.

What we are not claiming

Most security pages are a wall of badges. Here is the other list, because a vendor who tells you the limits before you ask is easier to check than one who does not.

No SOC 2 report There is no audit and no report. If a funder requires one, we are not the right answer today and we will tell you that on the first email rather than the fourth.
No HIPAA attestation For most homeless services data the governing regime is HUD and HMIS rather than HIPAA. If your situation is genuinely a HIPAA one, that is a conversation with a person and not a checkbox on a page.
No uptime guarantee We do not offer a service level agreement and we do not publish an uptime figure. Quoting one we have not committed to contractually would be marketing rather than a promise.
No implementation details We do not publish specifics about encryption schemes or credential storage. Publishing them helps an attacker more than it helps you evaluate us, and the structural facts above are the part you can actually check.
Has a funder sent you a security questionnaire?
Send it over. We will answer it directly, including the questions where the honest answer is no.
hello@illumipath.io