Current application controls
The public landing page is separate from the practice workspace. The workspace requires a signed-in platform identity and active owner or team permission. Records APIs enforce authorisation server-side, including when a page control is hidden or a direct request is made.
Roles distinguish clinical and billing access. Mutating requests check the request origin when supplied. The rich-text editor sanitises supported HTML. Payment history and record-change activity support review. These controls do not by themselves establish a complete compliance programme.
Storage and limitations
The deployed site uses HTTPS and cloud-hosted application storage. Patient records are not advertised as end-to-end encrypted. Application-level encryption is used for configured email credentials and connection tokens, not for every patient record. Direct email integration is paused.
No independent penetration-test report, ISO certification, HIPAA certification or POPIA compliance certification has been established for CounselR. Exact hosting locations, provider agreements, incident procedures and recovery commitments still require confirmation before clinical deployment.
Your part in protecting records
Use a protected device, keep browser and operating-system updates current, and avoid leaving a workspace open on shared computers. Grant the minimum team role needed and remove access when it is no longer appropriate.
Downloaded backups and reports may contain highly sensitive information. Store them in an access-controlled location, use an approved sharing method, check recipients and avoid public links. An exported file is not protected by workspace permissions once it leaves the application.
Report a vulnerability or incident
Email support@counselr.co.za with the affected page, approximate time and a brief description. Do not include real patient data, credentials or a full database copy. Ask for a secure channel before sharing sensitive evidence.
Test only with your own authorised account and non-production sample records. Do not access other users’ data, disrupt service or continue an exploit after demonstrating the issue. There is no published paid bug-bounty programme.
If you suspect a data incident, restrict compromised access and contact the practice owner and support promptly. Investigation and any required notifications must be handled under applicable law and provider arrangements. This draft does not promise a response deadline or that an incident can always be prevented.
Questions? Contact support@counselr.co.za.
