Loading Blue Skies Mutual Aid

Security Practices

Security Practices

These are the protections we have in place today, described plainly. They are our own statements — we do not hold a SOC 2 report or any security certification, and we do not claim one.

Last updated: September 13, 2026

In transit

Every page and form is served over HTTPS only, with strict transport security and a content security policy. There is no unencrypted version of the site.

At rest

Sensitive client information — case notes, location notes, closure reasons, referral and assistance notes, and volunteer phone numbers — is encrypted in the database with a key held outside it. Bank-link credentials for our accounting integration are encrypted the same way. Anything deliberately kept readable (for example a name used for search) is recorded internally with the reason.

Who can see what

Every table enforces row-level security, and permissions are checked on the server on every request, never in the browser. Privileged roles live in a separate table. Sensitive actions require re-authentication with a second factor.

Audit logging

Reads and changes to protected information are written to a tamper-evident audit log recording who accessed what and why. Entries are retained on a documented schedule and pruned afterward.

Health information

We follow HIPAA-aligned practices: written policies, annual workforce training, business associate agreements before sharing protected information, a disclosure log, periodic access reviews, and a breach-response process. HIPAA has no certificate — these are self-attested practices.

Reporting a vulnerability

Email security@blueskiesma.com with the details and steps to reproduce. Please give us a reasonable chance to investigate and fix before any public disclosure.

We will acknowledge your report, keep you updated, and credit you if you would like. We do not offer a paid bounty.

See also our privacy notice and subprocessors list.