Data security

Your supervision records are protected. Here's how.

AuditHalo handles compliance documentation. The bar for how we protect that data is high — and we'll tell you exactly what's in place, not marketing-speak.

What's in place

Built to hold up in an audit — including a security one.

Authentication

Passwords are bcrypt-hashed. Sessions are stored in HttpOnly cookies scoped to app.audithalo.com — never sent to the marketing site or any third party.

Data storage

All data is hosted on Neon Postgres (US-East-1) and served via Vercel (US-East). All traffic uses TLS 1.3 in transit. Data at rest is encrypted by the underlying cloud providers.

Tamper-evident audit packages

Every evidence package is SHA-256 hashed at the moment of sealing. The hash is stored with the package. If a record is altered after signing, the hash won't match — independently verifiable.

Immutable audit log

Every signature, rule-version change, and evidence-package creation is logged immutably per organization with 7-year retention — matching most state board record requirements.

Questions about how we handle your data?

We'll answer anything. No sales pitch.

Contact us