Security isn't a page we bolted on — it's why several of the architectural defaults exist. Here's the posture.
Only the fields a sync needs are ever moved or stored.
Per-employer credentials, mappings, and data, fully separated.
Every change and operator action is logged and reviewable.
Client, staff, and system-owner roles scope what's visible — staff access is granted per capability.
Standard encryption on every credential and record.
Operator redaction on support threads; data kept only as needed.
Security review is part of every release, not an annual event.
Want the security detail for your compliance review? We'll walk your team through it. security@tandemlink.net