How we protect your agency's data
Last updated: July 2026
All connections to Visiting Systems use TLS (HTTPS) encryption — between your browser and our servers, your caregivers' phones and our servers, and our servers and every service we rely on. Modern security headers (HSTS, content security policy, clickjacking protection) are enforced on every response.
Sensitive client fields — addresses and care notes — are protected with field-level AES encryption before they are stored, using authenticated encryption (AES-CBC with HMAC-SHA256 integrity verification). Encryption keys are stored separately from the database.
The full database is backed up daily to geographically separate storage. Every backup is AES-encrypted before it leaves our servers, so the storage provider never holds a readable copy. Restore procedures are documented and tested on a recurring schedule, with a 24-hour recovery point objective — meaning a worst-case failure costs at most one day of data, and in practice far less.
Your agency's data belongs to your agency — full stop. You can export your visit and payroll records as CSV at any time, directly from the dashboard, with no request needed. If you leave, we delete your agency's data on request. We never sell data or use it for anything other than operating the service for you.
Administrative actions — creating users, reassigning visits, changing roles, billing changes, and more — are recorded in a per-agency audit log, visible to your administrators in the dashboard.
GPS check-in verification requires explicit caregiver consent before any location data is collected, consistent with the Texas Data Privacy and Security Act. Location is captured at check-in and check-out only — caregivers are never tracked continuously.
All payments are processed by Stripe, a PCI-DSS Level 1 certified processor. Card numbers never touch our servers.
The platform is monitored around the clock with automated health checks and alerting. Email authentication (SPF, DKIM, DMARC) protects messages we send — and prevents others from impersonating our domain.
We believe you should know exactly which vendors are involved in running the service. The complete list:
That's the whole list — no analytics trackers, no advertising pixels, no data brokers. We update this page when the list changes.
If you believe you've found a vulnerability or have a security question, contact us at support@visitingsystems.com. We read every report and respond promptly.