Security & trust

Claims you can
check for yourself.

Sapphire runs where a mistake costs money, a survey finding, or a resident’s care. So every guarantee below is described as a mechanism — something that either is or is not in the code — rather than as a badge. The last section says plainly what we are not claiming yet.

  • 01

    Your password is never entered in Sapphire

    Sign-in happens on your identity provider’s own page, over an authorization-code flow with PKCE. Sapphire receives a verified identity token back — never your credentials. There is no password field anywhere in the product.

  • 02

    Access is decided on the server, every request

    Which applications, facilities and records you can reach is resolved at the data boundary, not by anything the browser is told. Knowing or typing a URL does not grant access, and a mistake in a screen does not become a disclosure.

  • 03

    Every record belongs to a facility

    Facility scope is part of the data model rather than a filter applied on the way out. Authorization remains active even when a screen or a service makes a mistake, which is why we describe the boundary as forced rather than applied.

  • 04

    Sessions are short-lived by design

    Your session is held in a short-lived, HTTP-only cookie that page scripts cannot read, and it is cleared when you sign out. The browser holds a session reference, not your identity.

  • 05

    PHI is handled on a minimum-necessary basis

    Modules that touch protected health information are marked as such in the registry, and access to them is granted deliberately rather than by default. A role that does not need clinical data does not receive it.

  • 06

    Uncertainty is named, not guessed

    Missing policy or uncertain data produces a named unavailable state rather than a plausible number. Dates, currencies, sources and effective policy stay attached to every operating fact, so a figure can be traced back to what produced it.

What we are not claiming

The absence of a claim is also information.

Most vendor security pages are a list of logos. This one is shorter on purpose: a claim we cannot substantiate today is a claim we will not print.

  • No third-party security certification is claimed. If you require one, ask us where that work stands rather than reading it into this page.
  • No availability or uptime figure is published, because the product is in private preview and any number would be meaningless.
  • The hosted preview environment contains synthetic demonstration data only — no customer records and no resident records.
  • Contractual terms, including any business associate agreement, are handled in the commercial conversation, not asserted here.
Reviewing Sapphire?

Send us the questionnaire.

We answer security and procurement reviews directly, including the questions where the honest answer is “not yet.”