Trust and security
What happens to your residents' information.
Plain answers to the questions owners and their advisors ask before putting resident charts in someone else's software. This page describes controls that are in place today. It is not a certification.
Where is the data hosted?
Tendera runs on Amazon Web Services in the United States. The production database is Amazon RDS for MySQL, deployed across two availability zones, with storage encrypted at rest.
- Automated backups with point-in-time recovery retained for 14 days.
- Deletion protection enabled on the production database.
- Uploaded documents and photos live in private, encrypted object storage.
- The database is not reachable from the public internet.
Is it encrypted?
- In transit: every connection to Tendera uses HTTPS, with HTTP Strict Transport Security enabled.
- At rest: database storage and uploaded files are encrypted by the hosting service.
- Extra layer: selected sensitive clinical fields are additionally encrypted by the application before they reach the database.
Who can see what?
Every operator gets its own organization. Access to data is scoped to that organization on the server, and within it by role and by facility.
- Caregivers see the facility they work in.
- Managers see the homes they are assigned to.
- Owners see every home in their organization.
- Narrower roles exist for kitchen, billing, and inspection access.
- Audit-log access is restricted to authorized administrative roles.
How is sign-in protected?
- Passwords are stored as bcrypt hashes, never in plain text.
- Multi-factor authentication is available to every user, using authenticator apps (TOTP) with one-time backup codes. Administrator and billing roles are required to enroll.
- Login endpoints are rate-limited, and repeated failures trigger progressive back-off and a temporary lock.
- Error messages do not reveal whether an account exists.
Is there an audit trail?
Tendera keeps application audit records for important activity: sign-ins, MFA events and lockouts, access to the audit log itself, and actions on clinical, compliance, and billing surfaces where they are instrumented.
Audit records support your own review. They are not offered as a substitute for your organization's compliance recordkeeping.
How is the application itself secured?
- Protection against cross-site request forgery on every state-changing request.
- A Content Security Policy that blocks inline scripts the application did not issue.
- Authorization enforced on the server for protected capabilities.
- Upload type and size controls, with files stored privately.
- Container images scanned for known vulnerabilities on every build; deployments use short-lived cloud credentials, not stored keys.
- Error reports are scrubbed of sensitive fields and health-information patterns before they leave the application.
What Tendera has not done yet
Tendera has not been independently audited against SOC 2, HITRUST, or ISO 27001, does not describe itself as certified under those frameworks, and has not had a third-party penetration test. HIPAA has no product certification; Tendera is built to support your organization's HIPAA obligations, and this page is a factual description of the controls in place rather than a guarantee.
Formal uptime, recovery-time, and recovery-point commitments are not published. If a formal assurance is a requirement for your organization, ask. You will get a straight answer about current status.
Business Associate Agreement
The AWS services Tendera runs on are covered by Tendera's AWS Business Associate Agreement. Tendera can execute a Business Associate Agreement with covered customers; ask before onboarding so it is in place before any protected health information is entered.
Your side of the arrangement
- Give each staff member the narrowest role that fits their job, and remove access when they leave.
- Do not share accounts. Turn on MFA for anyone whose role does not already require it.
- Secure the phones and shared workstations your staff use.
- Your licensing and regulatory obligations remain yours; Tendera helps you track them.
A written Security and Trust Overview with more detail is available on request for vendor reviews.
Questions
Security questions and vendor reviews.
Write to hello@tendera.care and mention that the request is security or vendor-review related so it is routed correctly.
Book a 20-minute demo