Security & HIPAA
Last reviewed: September 2026
This page describes how casedaisy handles your data today. Everything below is true of the current product. We hold no third-party security certifications — we are not SOC 2 or ISO 27001 certified — and we would rather say so plainly than imply otherwise.
Data encryption
All traffic between your browser or phone and casedaisy runs over TLS. Your data is stored in a managed PostgreSQL database where data at rest is encrypted. File uploads are stored in the same managed storage service and are served through access-controlled URLs rather than being publicly listed.
Access controls
Every table carries row-level security policies, enforced by the database itself rather than by application code. Each account can read and write only its own records; team and agency data is visible only to members of that organization, and a client record shared with a co-therapist is visible to that person because a sharing record exists, not because the query asked nicely. Roles are stored in a dedicated roles table, separate from user profiles, so a user cannot change their own permission level.
What we never do
- We do not sell or rent your data, or your clients' data, to anyone.
- We do not run advertising, and we use no third-party advertising or behavioural tracking cookies.
- We do not use your data to train AI models, and we do not allow our AI provider to train on it.
AI features and your data
Our AI features — visit-note drafting, schedule suggestions, and the scheduling copilot — send the specific text and schedule details needed for that request to Anthropic's Claude API and return a draft. Nothing is sent unless you trigger the feature. Every output is a suggestion: you read it, edit it, and decide whether to save it. Nothing an AI feature produces is filed or sent on your behalf. See the privacy policy for the full list of sub-processors.
HIPAA and BAAs
casedaisy is not HIPAA compliant by default. On standard plans, do not enter protected health information that requires HIPAA safeguards — scheduling details such as names, addresses, visit times, and authorization counts are what the product is designed to hold. A HIPAA-ready deployment with a signed Business Associate Agreement is available on the Enterprise plan. See pricing or email hello@casedaisy.com to arrange one.
Data ownership
Your data is yours. Mileage, earnings, authorization, and completion reports export to CSV and XLSX from the Reports section at any time, and custom reports can be built and exported the same way. For a full account export or permanent deletion, email hello@casedaisy.com and we will respond within 30 days.
Hosting
casedaisy runs on Supabase — a managed PostgreSQL database, authentication, file storage, and serverless functions. Subscription billing runs through Stripe, which holds card details; we never see or store a card number. Transactional email is sent through SendGrid, and addresses are geocoded and routes estimated through Google Maps.
Security questions
Reporting a vulnerability, reviewing us as a vendor, or asking anything else about security? Email hello@casedaisy.com.