Security
Security controls built into the architecture.
ConceptCare treats isolation, least privilege and auditability as platform primitives — the same controls apply to human users and to autonomous agents.
Encryption
TLS 1.2+ in transit and encryption at rest for all institute data and secrets.
Authentication
Email and password with verification, Google sign-in, password recovery and session management.
Authorization
Role-based access control with platform roles (user, staff, admin) and institute roles.
Data isolation
Every record is scoped to an institute and enforced at the database layer with row-level security.
Audit logs
Immutable activity trail for agent, workflow, permission and data-source changes.
Monitoring
Operational monitoring of platform health, execution failures and anomalous usage.
Student privacy first
Least-privilege access to student records, configurable retention and no training on your data by default.
Secrets management
Credentials for connected systems stored in managed secret storage, never in application code.
Agent safety
Autonomy inside explicit boundaries
An agent can only read the data sources it was granted and only perform the actions defined in its configuration. Higher-impact actions can require human approval inside the workflow.
Explicit action allowlists
Agents hold no ambient permissions; each tool and action is granted individually.
Human-in-the-loop steps
Sensitive workflow branches pause for approval before execution.
Full traceability
Every decision, data read and write is recorded with actor, time and payload metadata.
ConceptCare does not claim any third-party security certification or audit report on this page. Certification status, penetration test results and compliance documentation are shared through the enterprise security review process.
Start a security review.
We will walk your security team through architecture, controls and data handling.
