Trust

Security

Your license data matters, so protecting it is a default, not an afterthought. Here's how we do it — and where we honestly are.

Last updated June 18, 2026

Encryption

Your connection to TheraPath is encrypted in transit with HTTPS/TLS, and your data is encrypted at rest by our infrastructure providers. Nothing sensitive travels or sits in the clear.

Authentication

Sign-in is handled by a dedicated authentication provider (Clerk), with support for secure options like single sign-on. We never see or store your password.

Access controls

Your data is scoped to your account — every request is checked so you only ever see your own information. Internally, access to systems follows least-privilege principles and is limited to what's needed to operate and support the product.

Infrastructure

TheraPath runs on reputable cloud infrastructure (such as Vercel and Supabase) that maintains its own robust security practices, including network protection and regular patching.

Where we honestly are

We're an early-stage product, and we don't yet carry formal certifications like SOC 2 or a HIPAA attestation. We'd rather tell you that plainly than imply otherwise. What we can promise is that we build with security as a default, we collect only what we need, and we'll keep raising the bar as we grow.

Reporting a vulnerability

If you believe you've found a security issue, we want to hear from you. Please email support@therapath.app with the details, and we'll respond promptly. We're grateful to researchers who report responsibly.