Security

Scope every protected record to the signed-in agency and role.

Tiny checks agency and role before reading or changing child records, keeps files behind authenticated access, appends audit events, and excludes protected health information from account email.

Current posture

Agency-scoped access · append-only audit history · no PHI in email

These controls exist in the product today. Request current vendor agreements before entering production health information.
  • Every protected record operation is scoped to the active agency
  • Roles reduce access to the work a person is allowed to perform
  • Audit events are appended rather than rewritten
  • Child and family information never belongs in account email
Data boundaries

The agency boundary is enforced before the record is read.

Every request to read or change a protected record resolves the signed-in person, active agency, and role on the server. A route name or hidden button is never treated as the security boundary.

Agency isolation

Protected data functions receive the active agency scope before they touch child records, documents, or related operations.

Least-privilege roles

Owner, Admin, Member, Provider, and Guest access is checked against the action and record scope.

Append-only evidence

Audit events preserve who acted, when it happened, and which agency record changed without rewriting prior entries.
Accounts and sessions

People get controls they can understand and use.

A secure account still needs a clear recovery path. Tiny Solutions combines sign-in methods, session visibility, role management, and step-up checks around sensitive actions.

Sign-in protection

The account system supports passkeys, password and email flows, configured identity providers, and two-step verification.
  • Step-up checks for higher-risk actions
  • Single-use account links
  • Agency policy without exposing child data in the sign-in flow

Session and staff control

People can review signed-in devices. Agency admins can manage invitations, roles, and deactivation without deleting the operating history.
  • Sign out an individual device or other devices
  • Revoke or resend a pending invitation
  • Preserve attribution when a staff account is deactivated
Protected information

Each outside service gets the minimum data for its job.

Infrastructure boundaries matter because not every service in a software stack should receive child or family information.

Account email

Email messages carry sign-in and account information only. They never include a child name, case fact, clinical detail, or Medicaid ID.

Files

Child-record files stay behind authenticated, agency-scoped access instead of public document links.

Subscription billing

Stripe receives the information needed to manage the agency subscription. It does not receive child records or EI Hub claim details.
Shared responsibility

Software controls do not replace agency policy.

HIPAA and FERPA obligations also depend on agreements, device practices, staff training, access reviews, and the agency choices made after setup.

Tiny Solutions controls

Product architecture, server-side permission checks, audit history, account security, vendor boundaries, and recovery behavior.
  • Agency-scoped data access
  • Role and caseload permission checks
  • Append-only audit history
  • No-PHI account email
  • Protected file access

Agency controls

Who receives access, which devices are approved, how staff handle records outside the product, and when permissions are reviewed.
  • Role assignment and periodic access review
  • Managed devices and local screen privacy
  • Staff training and incident procedures
  • Data entered into exports and outside systems
Request trust materials
Security review

Bring the real questionnaire.

Send the controls your agency must verify. The answer should name what exists, what is inherited from infrastructure, and what still depends on agency policy.

Do not include child or family information in the questionnaire or email.