Security & privacy
Built so the family stays in control
A care record holds the most sensitive information a person has. Here is exactly how Tendfuls protects it, who can see it, and how you take it with you.
Encryption everywhere
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Attachments are stored encrypted with keys managed separately from the data.
Server-side audited access logging
Every read and write is logged on the server, not the device, so it can't be bypassed or edited. The record owner can see the full log at any time.
Time-limited and revocable access
Invitations can expire automatically. Revoking access takes effect immediately across all devices, and the revocation itself is logged.
HIPAA-ready, BAA available
Tendfuls is designed to meet HIPAA's administrative, physical and technical safeguards. Organizations and covered providers on the Growth plan can sign a Business Associate Agreement.
One-click export, no lock-in
The owner can export the complete record as PDF, CSV, JSON and a ZIP of attachments at any time, without contacting support and without waiting.
EU data residency and GDPR
Tendfuls is a Spanish company. Records for customers in the EU and UK are stored in EU data centres, and we act as a processor under GDPR for the data families and providers enter.
Strong sign-in
Two-factor authentication for every account, mandatory for provider and organization accounts, with session review and remote sign-out.
Backups and availability
Encrypted backups are taken continuously and tested regularly. Crisis protocols remain readable offline once they've been opened on a device.
Who can see what
Tendfuls staff cannot browse records. Support access is only possible when the record owner grants it, for a limited window, and it appears in the access log like any other view.
| Who | What they can access | How it's controlled |
|---|---|---|
| Record owner (family) | Everything | Owner account; can add co-owners |
| Invited team member | Only the categories granted | Per-person, per-category permissions; can expire |
| Organization admin (Growth) | Records under the organization, within the roles defined | Role templates; audited |
| Tendfuls support | Nothing by default | Time-boxed grant by the owner; logged |
| Tendfuls engineers | No record content | Encrypted at rest; no browse tooling exists |
Questions about security or compliance?
We'll answer in writing, and we're happy to complete vendor questionnaires for organizations.