ConceptCare

Security

Security controls built into the architecture.

ConceptCare treats isolation, least privilege and auditability as platform primitives — the same controls apply to human users and to autonomous agents.

Encryption

TLS 1.2+ in transit and encryption at rest for all institute data and secrets.

Authentication

Email and password with verification, Google sign-in, password recovery and session management.

Authorization

Role-based access control with platform roles (user, staff, admin) and institute roles.

Data isolation

Every record is scoped to an institute and enforced at the database layer with row-level security.

Audit logs

Immutable activity trail for agent, workflow, permission and data-source changes.

Monitoring

Operational monitoring of platform health, execution failures and anomalous usage.

Student privacy first

Least-privilege access to student records, configurable retention and no training on your data by default.

Secrets management

Credentials for connected systems stored in managed secret storage, never in application code.

Agent safety

Autonomy inside explicit boundaries

An agent can only read the data sources it was granted and only perform the actions defined in its configuration. Higher-impact actions can require human approval inside the workflow.

    Explicit action allowlists

    Agents hold no ambient permissions; each tool and action is granted individually.

    Human-in-the-loop steps

    Sensitive workflow branches pause for approval before execution.

    Full traceability

    Every decision, data read and write is recorded with actor, time and payload metadata.

ConceptCare does not claim any third-party security certification or audit report on this page. Certification status, penetration test results and compliance documentation are shared through the enterprise security review process.

Start a security review.

We will walk your security team through architecture, controls and data handling.