Therapeuo security — what is enforced, and what we do not claim
Security & data protection

What is enforced, and what we do not claim.

A counselling record is among the most sensitive data an organisation can hold. Below is what the platform actually does about that — and, in the same place rather than a footnote, what it does not.


Enforced, not configured

An administrator reads no clinical record

Not hidden in the interface — refused in the data layer, for every route that touches a note, a journal or an intake. Climbing the ladder means managing more and reading less. Proven by scope proofs that run without a database and fail the build.

The audit log records that, never what

It records that something happened, never what it said — no journal text, no transcript lines, no identity numbers. Append-only at the database itself, which refuses update, delete and truncate. Enforced by a migration, not by convention.

Nothing clinical reaches an overseas model

Every table is classified on both axes of the government data scheme, and clinical content is the most restricted class there is. Where the classification forbids it, the drafting assistant returns an empty form rather than quietly sending the text abroad.

The registration logbook keeps itself

Clinical and supervision hours accumulate out of sessions already recorded, toward the 600 and 60 a counsellor needs. Endorsement is a supervisor’s act, never the subject’s own — and hours survive a client’s deletion, because the work was genuinely done.

How it is put together

Clinical data is not on the public interface

The schemas holding notes, journals and intake are not exposed to the browser API at all. There is no path from a leaked browser key to a session note — every read goes through server code that has already resolved who is asking.

A query without a caller is treated as a defect

The access rules live in one file that imports no framework, so they can be proven from a plain script with no database. Adding a rule means adding a proof, and the proofs fail the build.

Everything is classified, and unclassified fails

A new table added without a classification turns the operator’s compliance page red rather than passing quietly. Client areas refuse anonymous access in production — tested, not promised.

Signing in, and staying signed in safely

A long session with a short idle lock: after fifteen minutes the device asks for biometrics again rather than signing anyone out mid-conversation. It shields a phone left on a table; it is not the authentication boundary and is not described as one.


What we do not claim

· No certification or accreditation beyond the PDPA, which is the mandatory floor rather than an achievement.

· No claim to diagnose, to score a person, or to predict what they will do.

· Session recording and transcription are not switched on, because no supplier has been chosen that can hold session audio in region.

· Where a control is not yet independently attested, the standards register says so, including the ones outstanding today.


The register behind all of this is measured against the running system rather than written from memory, and it is public — no account, no sales conversation, including whatever is failing today.

The standing invitation

Doing due diligence on behalf of a partner?

The service and data protection statement is generated from the running system and can be downloaded without asking us. Bring your data-protection officer, your IT auditor or your most sceptical board member — if you need something the statement does not answer, ask directly and the answer goes in writing.

Ask a question Request a demo
A single skeleton key on a plain ground
Photo by Everyday basics on Unsplash