ElderOrbit
Terms of ServicePrivacy Policy & Data HandlingField Test / Beta ConsentHIPAA & Health Data Notice

Version: security_audits@2026-07-27

Effective: July 27, 2026

This page is maintained by the app operator. It is not legal advice and not independently verified by Lovable. Confirm all terms with qualified counsel before relying on them.

Security & Compliance Standards

This page describes the security practices currently in place for ElderOrbit, operated by ElderOrbit, Inc.. We publish it for transparency with families, caregivers, and beta participants evaluating whether ElderOrbit fits their needs.

1. Infrastructure & Hosting

[PLACEHOLDER — name providers/regions before publishing.] ElderOrbit runs on managed cloud infrastructure with a hosted Postgres database and row-level security enforced at the database layer.

2. Encryption

[PLACEHOLDER — confirm specifics with engineering.] Data is encrypted in transit (TLS) between your browser and our servers, and at rest in the underlying database.

3. Access Controls & Row-Level Security

Access to care data is scoped per patient and per role using database-enforced row-level security policies, not just application-layer checks — a caregiver or family member can only read and write data for patients they are explicitly added to.

4. HIPAA / BAA Readiness Status

ElderOrbit is not yet operating under signed Business Associate Agreements with its infrastructure vendors. Protected Health Information features are gated behind an organization-wide flag and remain off until that readiness work is complete — see our HIPAA & Health Data Notice for details.

5. Audit Logging & Monitoring

Changes to sensitive records are recorded in an internal audit log capturing who made a change and when, to support accountability and incident investigation.

6. Vulnerability Management & Security Testing

[PLACEHOLDER — no formal third-party penetration test has been performed yet; cadence to be determined.] We run automated checks against our database security policies as part of our development process.

7. Incident Response & Breach Notification

[PLACEHOLDER — formal runbook and notification timeline to be finalized.] In the event of a security incident affecting your data, we will notify affected users and take reasonable steps to remediate, consistent with applicable law.

8. Sub-processors & Third-Party Vendors

[PLACEHOLDER — list finalized vendors once confirmed.] We rely on a small number of vendors for hosting, email delivery, and (optionally) SMS — each bound by confidentiality obligations, as described in our Privacy Notice.

9. Certifications & Compliance Roadmap

[PLACEHOLDER.] ElderOrbit is not currently SOC 2 or HITRUST certified. This page will be updated if and when that changes.

10. Reporting a Security Concern

If you believe you have found a security issue, please contact us at support@elderorbit.ai so we can investigate promptly.

© 2026 ElderOrbit. All rights reserved.
Legal & Trust CenterTerms of ServicePrivacy NoticeHIPAA NoticeBeta ConsentSecurity & Compliance