Security & trust

The most sensitive data a family will ever hand over.

Medical histories, legal agreements, payment schedules, and the identities of everyone involved in creating a child. Below is how it is held, who can reach it, and — the part most vendors leave out — what we deliberately refuse to do with it.

Encrypted in transit and at rest

TLS on every connection, encryption at rest on the database and on stored documents. No unencrypted copy of a medical record exists anywhere in the system.

Isolated per agency

Each agency’s data is separated at the database layer, not filtered in application code. A query written for one agency cannot reach another’s families.

Access by role, not by trust

A coordinator sees the cases they carry. A viewer cannot edit. An admin cannot silently read a portal conversation without it appearing in the trail.

Who can see what

Four audiences on one record, each seeing only their part.

A surrogate and an intended parent share a journey but not a view of it. The hard part of this product is not storing the data — it is making sure each person sees exactly their share of it, every time, without a coordinator having to think about it.

Coordinator
Intended parent
Surrogate
Clinic
Journey progress
Full
Their own
Their own
Stage only
Medical records
Full
Their own
Their own
If shared
Legal agreements
Full
Their own
Their own
None
Payment milestones
Full
Their own
Their fees
None
Messages
Full
Their own
Their own
Their own
The other party’s identity
Full
If agreed
If agreed
None

Visibility is set per document and per message, not per folder — so a medical record shared with a clinic does not become visible to everyone who can see the case.

The refusals

What we will not do with your data.

Most of a security page is a list of things a vendor has. This is the list of things we have decided against — which is usually the more useful one, because it is the part that cannot quietly change once you have signed.

We do not hold anyone’s money

Payments are tracked against milestones and never processed here. Escrow, transfers and card handling stay with the people already licensed and insured to do them. We are not in the flow of your clients’ funds.

We do not train models on your families

Your data is not used to train anything, ours or anyone else’s. A surrogacy journey is not training material, and no amount of product improvement would justify it.

We do not put our brand in front of your clients

The portals are yours end to end — your name, your address, your colours. Your clients never learn we exist, and we never contact them for any reason.

We do not sell, share, or analyse across agencies

No benchmarking product built from your book, no aggregate data sold onward, no “industry insights” assembled from other people’s families. Your data leaves your tenant only when you export it.

The audit trail

Every action, attributable.

Who did what, when, and what it changed — recorded on the case rather than reconstructed from memory afterwards. When a family, a lawyer or a regulator asks how a decision was reached, the answer is a record you can hand over, not an account of what someone remembers.

This matters most at exactly the moments it is hardest to reconstruct: a match that was declined, a clearance that expired, a payment that was queried.

Activity · case 21414 Sept
09:14

Match accepted

Case 214 moved Matching → Legal

D. Rivera · coordinator

09:15

Portal invitation sent

To both parties, in their own language

System

11:02

Document signed

Gestational agreement · e-signature

A. Adeyemi · intended parent

11:02

Visibility changed

Shared with attorney, not with clinic

D. Rivera · coordinator

Where we are still building

The part a security page usually hides.

We are a young platform. Some of what a large agency’s procurement team will ask for is in place, and some is not yet. You should hear which is which from us, now, rather than from a questionnaire in month three.

In place today

  • Encryption in transit and at rest
  • Tenant isolation at the database layer
  • Role-based access and per-item visibility
  • Append-only audit trail on every action
  • A single, named hosting region

Not yet in place

  • SOC 2 Type II — not yet certified; audit not yet begun
  • Third-party penetration test — not yet commissioned
  • Customer-managed encryption keys — planned for licence agreements
  • HIPAA BAA — not yet offered; ask us and we will tell you where it stands

If your procurement process needs something not listed here, ask. We would rather tell you we do not have it yet than discover the gap together during an onboarding.

Send us your security questionnaire.

We will fill it in properly, mark honestly what we do not yet have, and tell you where the rest stands. No security theatre.

Talk to usSee what it does
Security & trust — SRM Platform