Security at Visiting Systems

How we protect your agency's data

Last updated: July 2026

Your agency trusts us with sensitive information about your clients and caregivers. We treat that responsibility as a core part of the product — not an afterthought. This page describes the safeguards protecting your data today. Prefer a copy to share? Download the one-page Security Overview (PDF).

Encryption in transit

All connections to Visiting Systems use TLS (HTTPS) encryption — between your browser and our servers, your caregivers' phones and our servers, and our servers and every service we rely on. Modern security headers (HSTS, content security policy, clickjacking protection) are enforced on every response.

Encryption at rest

Sensitive client fields — addresses and care notes — are protected with field-level AES encryption before they are stored, using authenticated encryption (AES-CBC with HMAC-SHA256 integrity verification). Encryption keys are stored separately from the database.

Encrypted off-site backups

The full database is backed up daily to geographically separate storage. Every backup is AES-encrypted before it leaves our servers, so the storage provider never holds a readable copy. Restore procedures are documented and tested on a recurring schedule, with a 24-hour recovery point objective — meaning a worst-case failure costs at most one day of data, and in practice far less.

Your data is yours

Your agency's data belongs to your agency — full stop. You can export your visit and payroll records as CSV at any time, directly from the dashboard, with no request needed. If you leave, we delete your agency's data on request. We never sell data or use it for anything other than operating the service for you.

Access control

Audit trail

Administrative actions — creating users, reassigning visits, changing roles, billing changes, and more — are recorded in a per-agency audit log, visible to your administrators in the dashboard.

Location privacy and consent

GPS check-in verification requires explicit caregiver consent before any location data is collected, consistent with the Texas Data Privacy and Security Act. Location is captured at check-in and check-out only — caregivers are never tracked continuously.

Payments

All payments are processed by Stripe, a PCI-DSS Level 1 certified processor. Card numbers never touch our servers.

Availability

The platform is monitored around the clock with automated health checks and alerting. Email authentication (SPF, DKIM, DMARC) protects messages we send — and prevents others from impersonating our domain.

Subprocessors

We believe you should know exactly which vendors are involved in running the service. The complete list:

That's the whole list — no analytics trackers, no advertising pixels, no data brokers. We update this page when the list changes.

Reporting a security concern

If you believe you've found a vulnerability or have a security question, contact us at support@visitingsystems.com. We read every report and respond promptly.