Security & compliance
For county procurement, partner due diligence and funders.
Hope and Key handles sensitive information for people in housing crisis. This page documents how we protect it — the same practices we complete in security questionnaires for government contracts.
Access control
- Every personal record is scoped to its owner at the database level — a signed-in person can only ever read and change their own profile, applications, saved shelters and waiting-list entries.
- Row-level security rules are enforced by the database itself, not by app code, so a bug in the app cannot expose another person's record.
- Staff (case workers) receive a separate role stored independently of user profiles. Staff see only what care requires: the conversation, the person's profile fields and the applications they filed.
- Partnership inquiries are visible to staff only, never publicly.
Data handling & retention
- Personal data is stored in a managed cloud database; it is never sold, shared with advertisers, or used to train models.
- Shelter submissions and photos stay in private storage until a reviewer verifies the listing; nothing publishes automatically.
- People can view, edit and delete their own data from the app, and can request full account deletion by email at any time.
- Aggregate, de-identified counts (people served, applications filed) are what we publish on our partners page — never individual records.
Infrastructure
- All traffic is encrypted in transit (HTTPS/TLS), including photo uploads.
- Hosting runs on managed cloud infrastructure with isolated database credentials; the privileged service key is never present in the app or the browser.
- Server-side code runs in a sandboxed runtime with no shared filesystem between tenants.
- Backups and database monitoring are handled by the managed cloud provider.
People & governance
- Staff accounts are granted individually and can be revoked instantly by removing the role.
- Case workers are accountable for the conversations in their inbox; the platform records who sent every message.
- We keep a full audit trail in the platform logs of access to case conversations.
For procurement & contracts
We complete vendor security questionnaires and can sign data-protection agreements as part of a county or provider contract. Full details of what we collect and why are in our Privacy Policy.
Responsible disclosure
Found a vulnerability? Email us and we will respond within one business day and keep you informed through the fix.
Contact
Security, privacy and compliance questions: privacy@hopeandkey.com. Partnership questions: use the partner form.