Start Your Care Space
Security

How we approach security

An overview of security practices we use to protect CareNestHQ™ websites, services, and user information.

Last updated: June 27, 2026

Secure Cloud Infrastructure

CareNestHQ uses industry-standard hosting, encryption in transit, and operational security practices described in public materials.

You Control Your Data

Users decide what caregiving information they enter, retain, and share within their care space.

Private by Design

CareNestHQ is architected so family care spaces default to private, invite-based collaboration rather than public sharing.

Overview

Security overview

We use industry-standard technical and organizational measures to help protect information processed through CareNestHQ™. Our approach includes:

  • Encryption in transit — HTTPS/TLS for data transmitted between your browser and our services
  • Authentication controls — account sign-in and session protections where product features require accounts
  • Access controls — limiting internal and vendor access to systems on a need-to-know basis
  • Secure hosting infrastructure — cloud providers with established security programs (such as Cloudflare, Supabase, and Vercel)
  • Monitoring and logging — operational logging to detect anomalies and investigate issues
  • Backup procedures — data backup practices through our infrastructure providers where applicable
Your account

Account security recommendations

You can help protect your information by:

  • Using a strong, unique password for your CareNestHQ™ account
  • Enabling multi-factor authentication (MFA) when we make it available
  • Keeping devices and browsers updated with current security patches
  • Avoiding shared or public devices for sensitive care coordination tasks
  • Signing out on shared computers and reviewing active sessions when offered

Additional detail about how we handle data appears in our Privacy Policy — Security Practices section.

Disclosure

Responsible disclosure

If you believe you have found a security vulnerability affecting CareNestHQ™, please report it responsibly so we can investigate and remediate.

Email: security@carenesthq.com

Include a description of the issue, steps to reproduce, and the potential impact. Please do not publicly disclose vulnerabilities before we have had a reasonable opportunity to address them.

Disclaimer

Security disclaimer

No electronic system can be guaranteed to be completely secure. We work to reduce risk, but we cannot eliminate it entirely. You use CareNestHQ™ at your own risk, subject to our Terms of Service.

See also: Legal Center · HIPAA Position Statement