Security & Compliance

Last Updated: February 17, 2026

At SuperviseABA, we take the security of your data seriously. We employ industry-standard security measures to ensure your supervision records are safe, private, and always available.

Encryption

Data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption standards.

Infrastructure

Hosted on Vercel and Supabase with automated backups and 99.9% uptime SLAs.

HIPAA Compliance Statement

Important: SuperviseABA is designed as a Administrative Tool for tracking supervision hours, not as an Electronic Health Record (EHR).

While we implement HIPAA-grade security measures (encryption, access controls, audit logs), users strictly must not enter Protected Health Information (PHI) such as full client names, dates of birth, or medical diagnoses into the system. Please use initials or internal client IDs only.

Data Protection Measures

  • Access Control: Strict role-based access ensuring only you and your authorized supervisor/supervisee can view records.
  • Audit Logging: All critical actions (creating, signing, editing sessions) are permanently logged for audit trails.
  • Payment Security: All financial transactions are processed by Stripe, a PCI-DSS Level 1 compliant provider. We never touch your credit card data.

Vulnerability Reporting

If you believe you have found a security vulnerability in SuperviseABA, please report it to us immediately at security@supervise-aba.com.