Trust
Security
Your license data matters, so protecting it is a default, not an afterthought. Here's how we do it — and where we honestly are.
Last updated June 18, 2026
Encryption
Your connection to TheraPath is encrypted in transit with HTTPS/TLS, and your data is encrypted at rest by our infrastructure providers. Nothing sensitive travels or sits in the clear.
Authentication
Sign-in is handled by a dedicated authentication provider (Clerk), with support for secure options like single sign-on. We never see or store your password.
Access controls
Your data is scoped to your account — every request is checked so you only ever see your own information. Internally, access to systems follows least-privilege principles and is limited to what's needed to operate and support the product.
Infrastructure
TheraPath runs on reputable cloud infrastructure (such as Vercel and Supabase) that maintains its own robust security practices, including network protection and regular patching.
Where we honestly are
We're an early-stage product, and we don't yet carry formal certifications like SOC 2 or a HIPAA attestation. We'd rather tell you that plainly than imply otherwise. What we can promise is that we build with security as a default, we collect only what we need, and we'll keep raising the bar as we grow.
Reporting a vulnerability
If you believe you've found a security issue, we want to hear from you. Please email support@therapath.app with the details, and we'll respond promptly. We're grateful to researchers who report responsibly.