Security at Censiva
Censiva · Last updated June 29, 2026
Censiva is built for independent home health and hospice agencies, and we treat the trust you place in us as the foundation of the product.
No PHI by design
Censiva is a pre-admission referral workflow and territory-intelligence platform, designed to operate without storing Protected Health Information. It tracks the business of referral relationships - sources, status, documents requested, BD activity - not patient clinical data. Because PHI never enters the system by design, the largest category of healthcare data risk does not apply.
Tenant isolation
Every agency's data is isolated at the database level with row-level security, scoped to your agency and enforced on every read and write by the database itself - not by application code that could be bypassed. We verify this isolation across agency boundaries as part of development.
Access controls
- New accounts require explicit approval before access.
- Roles (admin, intake, BDR/liaison) scope what each user can see and do.
- Authentication is protected by rate limiting and bot mitigation (Cloudflare Turnstile).
Encryption
Data is encrypted in transit (TLS) and at rest via our platform providers' managed infrastructure (Supabase, Vercel).
Infrastructure
Censiva runs on established cloud infrastructure (Supabase, Vercel).
Responsible disclosure
If you believe you've found a security issue, we want to hear about it. Please reach out to kevin@censiva.aiand we'll respond as quickly as we can.
Compliance
Censiva is designed to operate without storing Protected Health Information.
Questions about our security posture? Email kevin@censiva.ai.
Back to home