A counselling record is among the most sensitive data an organisation can hold. Below is what the platform actually does about that — and, in the same place rather than a footnote, what it does not.
Not hidden in the interface — refused in the data layer, for every route that touches a note, a journal or an intake. Climbing the ladder means managing more and reading less. Proven by scope proofs that run without a database and fail the build.
It records that something happened, never what it said — no journal text, no transcript lines, no identity numbers. Append-only at the database itself, which refuses update, delete and truncate. Enforced by a migration, not by convention.
Every table is classified on both axes of the government data scheme, and clinical content is the most restricted class there is. Where the classification forbids it, the drafting assistant returns an empty form rather than quietly sending the text abroad.
Clinical and supervision hours accumulate out of sessions already recorded, toward the 600 and 60 a counsellor needs. Endorsement is a supervisor’s act, never the subject’s own — and hours survive a client’s deletion, because the work was genuinely done.
The schemas holding notes, journals and intake are not exposed to the browser API at all. There is no path from a leaked browser key to a session note — every read goes through server code that has already resolved who is asking.
The access rules live in one file that imports no framework, so they can be proven from a plain script with no database. Adding a rule means adding a proof, and the proofs fail the build.
A new table added without a classification turns the operator’s compliance page red rather than passing quietly. Client areas refuse anonymous access in production — tested, not promised.
A long session with a short idle lock: after fifteen minutes the device asks for biometrics again rather than signing anyone out mid-conversation. It shields a phone left on a table; it is not the authentication boundary and is not described as one.
· No certification or accreditation beyond the PDPA, which is the mandatory floor rather than an achievement.
· No claim to diagnose, to score a person, or to predict what they will do.
· Session recording and transcription are not switched on, because no supplier has been chosen that can hold session audio in region.
· Where a control is not yet independently attested, the standards register says so, including the ones outstanding today.
The register behind all of this is measured against the running system rather than written from memory, and it is public — no account, no sales conversation, including whatever is failing today.
The service and data protection statement is generated from the running system and can be downloaded without asking us. Bring your data-protection officer, your IT auditor or your most sceptical board member — if you need something the statement does not answer, ask directly and the answer goes in writing.