Security

Family data deserves serious engineering and honest claims. Here is how Choice Labz™ is built, stated plainly.

Design commitments

  • Role-based access with least privilege: participant, facilitator, organization admin, and platform admin are separated at the database layer, not just in the interface.
  • Row-level security on every table; every server action re-verifies the caller.
  • Organizations are isolated: staff can only see their own organization's completion records.
  • Audit logging for administrative and security-relevant events.
  • Encrypted transport, secure session handling, rate limiting on public endpoints, and validation of all input.
  • No secrets in client code, and no third-party advertising or tracking SDKs.

Honest status

We do not claim SOC 2, HIPAA, FERPA, or court approval. Those are formal processes, and we will say so when and if they apply. What we offer today is a documented design, configurable institutional controls, and a willingness to complete due diligence with your security team.

Reporting a concern

If you believe you have found a security issue, please contact us through the contact page with the subject line "Security". Please do not include sensitive personal data in your report.