Security practices

CoverGrid holds schedules, attendance and employee records for long-term care buildings. This page describes the protections built into the product, in plain language, so your IT and compliance people can read it without a call.

Three levels of access, nothing shared

Every person signs in as an employee, a manager, or an administrator. Employees see their own schedule, points and requests. Manager tools and the administrator area are not reachable from an employee account — the rules are enforced by the database itself, not just hidden in the screen.

The database enforces the rules

Row-level security is switched on for every table that holds staffing or employee information, and each rule is written against the signed-in person. A request for someone else's record comes back empty, whichever screen or device it came from.

Encrypted on the way in and at rest

The site is served only over HTTPS, and the managed database stores data encrypted on disk. Passwords are never stored by the application; sign-in is handled by the managed authentication service.

Automatic sign-out on shared computers

Nurses' station computers get used by whoever is standing there. An administrator sets an idle limit, and the app signs the person out on its own once that time passes with no activity.

A change record for everything that matters

Schedule changes, call-offs, point adjustments, access changes and settings changes are written to a change record with who did it and when — including the ones the system makes for itself. An administrator can download it for any window.

Access reviews on a schedule

Administrators review the full account list on a set cadence, adjust anyone who no longer needs their level, and sign off. Accounts that have not signed in for 90 days and accounts with no matching staff record are flagged on that list.

Records are kept only as long as they are needed

Keep-until windows for the change record, message history and notifications are set by an administrator, and anything past its window is removed.

Kiosks and public endpoints are verified

Time-clock kiosks pair with a device key and are rejected without a valid one. Feeds from outside systems, like census and payroll connectors, require a private key that is never exposed to a browser. Text message delivery callbacks are verified against the sender's cryptographic signature.

Reporting a problem

If you believe you have found a security problem, contact your CoverGrid account owner directly and describe what you saw and how to reproduce it. Please do not test against a live building's data.

This page describes product controls only. It is not a certification, an audit result, or a legal commitment.