Security and privacy at Cara
Cara handles the first conversation a family has with your agency. That conversation contains information about a real person's health, so we treat it that way. Here is exactly what is in place today.
Encrypted end to end in transit and at rest
Every connection uses TLS, and stored data is encrypted at rest by the hosting platform. Integration credentials are held server side and never reach the browser.
Per-agency isolation and role-based access
Row-level security in the database scopes every query to a single agency. Within an agency, exporting data, deleting records permanently, and reading the access log are limited to owners and administrators.
Append-only access logging
Every view, creation, change, export, and deletion of a client record is written to a log your agency can search and export. Entries cannot be edited or removed, by us or by you.
Retention controls and permanent erasure
You choose how long calls, transcripts, and messages are kept. Anything past that window is destroyed automatically. A single action permanently erases one client and everything attached to them.
A boundary around AI
By default, AI scoring and drafting see initials and a coarse care category, not names, contact details, or health free text. Full-content AI processing is off unless you turn it on deliberately.
Automatic sign-out and security alerts
Sessions end after 15 minutes of inactivity. Owners are alerted on bulk exports, role changes, and integration changes.
HIPAA
Cara acts as a business associate to the agencies that use it. Every agency accepts a Business Associate Agreement inside the product before client health information can be stored, and the safeguards above map to the HIPAA Security Rule requirements for access control, audit controls, integrity, and transmission security.
To be direct about where we are: the technical safeguards are live, and we are working through signed agreements with each vendor in our chain. Current status for every vendor is published on our subprocessors page. We do not claim certification we do not hold, and we have not completed a SOC 2 or HITRUST audit.
Reporting a vulnerability
Email security@trycara.io with steps to reproduce. We acknowledge within 3 business days. Please do not test against another agency's data, and give us a reasonable window to fix before disclosing.