Security and access controls without vague compliance claims.

CareReady uses authenticated, role-aware access and server-side administrative controls. The current beta is still preparing for stricter HIPAA infrastructure.

Authenticated access

Supabase authentication supports email and Google sign-in. Protected application routes require an authenticated session.

Owner and caregiver roles

Role checks and home membership rules determine which homes, residents, and workflows a user can access.

Row-level database policies

Supabase Row Level Security limits authenticated access to records connected to the user’s home membership and role.

Audit activity

Operational and administrative actions create timestamped audit events for review and support.

Stripe-hosted billing

CareReady sends checkout and subscription-management activity through Stripe’s hosted billing surfaces.

Server-side administration

Global-admin operations use server routes and the Supabase service role; that key is never exposed to the browser.

The current beta is not a final HIPAA production environment.

Do not treat CareReady’s current beta as a completed HIPAA deployment until the compliance upgrade is finished and confirmed. Contact CareReady before using the product for workflows that require that assurance.

Have a security or compliance question?

Start with the home, add the team, and build the daily documentation workflow from there.