Each organization sees its residents.
Every table carries row-level security, and the account the application connects with cannot bypass it. A request carrying the wrong facility returns nothing at all — not a filtered list, nothing.
Security and record trust
Facility data is separated in the database, staff access follows the role, and a signed record cannot be silently changed. Those boundaries are enforced below the application, not promised by it.
Who can see information
These boundaries hold even if the application above them has a bug, because they are enforced by the database rather than by screen logic.
Every table carries row-level security, and the account the application connects with cannot bypass it. A request carrying the wrong facility returns nothing at all — not a filtered list, nothing.
Facility administrators, clinical staff, direct-care staff, and oversight users hold different permissions. Anything a facility can configure starts denied and has to be granted deliberately.
Deactivation takes effect on the next request. Higher-risk access is scoped, time-bound where needed, and written to the audit trail.
After a record is signed
Authorship, signature, time, and every later change stay legible. The database refuses the edit — there is no administrator override and no development bypass.
Before resident data
Each one closes on evidence, not on an assurance. The tag says what finishing it actually looks like.
Where the line is today
A security page that only lists strengths is not much use for diligence. Here is what is deliberately not true yet.
No real resident information exists in Everstead today. Development and testing run on invented data, and this marketing site collects business contact details only.
No certification, no third-party assessment, no independent verification. The controls described above are ours to demonstrate, and we will walk you through them rather than point at a badge.
There is no automatic deletion schedule and no disclosure-accounting workflow. Both are facility decisions, agreed and configured with you before go-live rather than assumed on your behalf.
Ask directly
Send it to a real person, or walk through the checks required before your facility goes live.