Security & Privacy

How we protect your professional records

CredenSync is built for licensed clinicians, educators, social workers, and small practices — people who need to know, at a glance, that the platform handling their credentials takes privacy seriously. This page explains, in plain English, exactly what we do (and don't do) with your data.

Your data lives in an encrypted, managed database

Every record you add to CredenSync is stored in a managed database that is encrypted at rest. Backups, snapshots, and the database itself sit behind the same encryption — no one outside our infrastructure can read a credential file in cleartext.

You only see your own records — and so does our team

Access is gated by role-based controls. Your dashboard only ever shows records tied to your account, and every server-side query is filtered to your user before a single row is returned. Our support staff do not browse your data to investigate issues — access is scoped and logged.

Every change to a record is captured in an audit trail

When a credential is added, edited, renewed, or archived, CredenSync writes a paired event that records who made the change and when. The audit trail is part of the same write as the change itself, so it cannot be skipped or edited out of band. You can review the timeline for any of your records at any time.

We do not sell, rent, or share your data

Your credential records are not a product. We do not sell, rent, trade, or share them with third parties for marketing or advertising — and we don't maintain advertising integrations to do so. The only people who ever read your records are you, and the support staff you explicitly grant a session to.

Traffic is encrypted in transit with HTTPS and TLS

Every request between your browser and CredenSync is served over HTTPS with modern TLS. Your password, your records, and your audit trail never travel in cleartext — whether you're signing in from a clinic desktop, a school laptop, or a personal phone.

A note on HIPAA: held to healthcare-grade care

Credential records — licenses, certifications, CE hours, contact details — are not Protected Health Information under HIPAA. Still, the people who trust CredenSync with their professional records deserve healthcare-grade protection, so we hold ourselves to that bar: encryption, access control, and a full audit trail, by default for every account.

Questions about your data?

If you want to know more about how a specific piece of information is stored, ask for a copy of the data we hold about your account, or want a record deleted, write to us directly. We answer these requests first — before anything else in the inbox — and typically reply within one business day.

Email credensync@polsia.app