Security & privacy
Trust is our product’s foundation
Healthcare workforce data — credentials, documents, schedules, payment records — deserves disciplined handling. Here is exactly how LocuPedia handles it: what we do, what we never do, and what we’re still working toward. No borrowed badges, no vague promises.
Our security principles
Four rules every decision answers to
These aren’t aspirations on a policy page — they’re the principles the product is built around, visible in how LocuPedia actually works.
Data minimization
We collect the workforce data a staffing workflow needs — and nothing beyond it. Patient information is never part of any LocuPedia workflow, and we don’t gather personal data “just in case.” Less data held means less data at risk.
Not hidden behind a permission, not restricted to staff — never collected. You cannot leak a field that doesn’t exist.
Least-privilege access
Every account sees only what its role requires — a department coordinator doesn’t see another department’s requests, and an organization never sees a clinician’s documents without an active opportunity between them. Access is scoped by default, not by request.
Accountability by default
Every action on the platform is attributable to a named individual and written to a reviewable audit record — who viewed, posted, applied, changed or closed what, and when. When something matters, you can always answer “who did this?”
The clinician sees these entries too — being watched works both directions here.
Honesty over marketing
We publish only what we do today. Where practice is still maturing — independent assessments, formal certifications — we say so plainly and tell you what’s on the roadmap, rather than borrowing credibility we haven’t earned.
- Encryption in transit & at rest, scoped roles, audit history Live today
- Independent security assessment On the roadmap
- Formal certification — announced only with results in hand On the roadmap
- Displaying badges we haven’t earned Never
This page is re-read and dated with every change — last reviewed October 2026. Changes to these rules appear here before they take effect.
We are not here to make a business out of your data. We are here so no clinic goes uncovered and no clinician is treated like inventory — and nothing you entrust to LocuPedia is for sale, rent or trade, to anyone, ever. Security isn’t our sales pitch; it’s the condition for being allowed to work in healthcare at all.
The promise every LocuPedia decision answers to — an eSora Labs companyHow we protect data
The controls behind the promise
Six concrete layers, described in plain language. If you’re evaluating LocuPedia for your organization, this is the level of specificity you should expect from any vendor.
Encryption in transit
Every connection between your browser and LocuPedia is encrypted with modern TLS — including every credential document upload and download.
- TLS on every connection, no exceptions
- Documents travel encrypted end to end
Encryption at rest
Stored data — profiles, credential documents, requests, records — is encrypted at rest, so information stays protected even where it lives.
- Databases and document storage encrypted
- Backups covered by the same standard
Access controls & permissions
Role-based permissions scope what each user can see and do — by facility, department and responsibility. Clinicians control the visibility of their own profiles.
- Roles for coordinators, reviewers, finance, admins
- Clinician-controlled profile visibility
Authentication & account security
Every user has an individual account — no shared logins — protected by a password policy and managed sessions, so access is personal and revocable.
- Individual accounts, always attributable
- Session management and sign-out controls
Bounded document sharing
Credential documents are visible only to the organization reviewing that specific opportunity — and only while the opportunity is active. Nothing is broadcast.
- Sharing tied to a real, active opportunity
- Access ends when the opportunity closes
Audit history
Requests, approvals, messages and changes are logged with the person and timestamp attached — a reviewable history of who did what, and when.
- Every decision attached to a named person
- Exportable for your own records and reviews
Clear boundaries
What we never do
Some commitments are easier to keep as absolutes. These are ours — held as product rules, not marketing lines.
- No patient information in staffing workflowsStaffing data and patient data are different worlds. LocuPedia stays in its own — patient information is not collected, not stored, not asked for.
- No selling or sharing personal data with advertisersProfiles and credential records exist to place clinicians in work they choose — nothing else, for anyone else.
- No displaying certifications or badges we haven’t earnedNo borrowed seals, no aspirational logos. When we earn a certification, you’ll see it here — not before.
- No access to your profile without your participationOrganizations see a clinician’s profile only through an opportunity the clinician is connected to. There is no silent browsing.
- No keeping data beyond its purposeRetention is bounded. When you delete your account, or a record reaches the end of its purpose, it is purged — except the minimum audit records the law requires, which we’ll list for you on request.
- No quiet changes to these rulesThese commitments change only in public: any change is posted on this page, with its effective date, before it takes effect — never buried in an update email.
How these stay true: they’re written into product requirements, not a policy PDF — a feature that breaks one of these rules does not ship, whoever asks for it. If you ever catch us near the line, report it below — that report lands with a named person, not a queue.
Your data rights
Your data stays yours
Both sides of the platform hold real, exercisable rights over their information — no tickets into a void, no fine print. Don’t take the sentence on faith: try the controls below.
Try it — your controls are real
Flip the switches. Watch what an organization sees.
Every clinician holds these switches from day one. Flip them and watch the organization’s view change on the right — this isn’t a promise about policy, it’s how the product behaves.
For clinicians
Your profile, credentials and work history belong to you.
- View and export your data. See everything on your record and take a copy with you, whenever you want.
- Control your visibility. You decide which opportunities connect you to an organization — your profile is never public.
- Request deletion. Ask for your account and personal data to be deleted, subject only to records we’re required to keep.
For organizations
Your requests, decisions and records are yours to keep and audit.
- Export your records. Requests, approvals and audit history export for your own compliance and review processes.
- Control team access. Add, change or revoke roles as people join, move and leave — access follows responsibility.
- Ask us anything. Security documentation is available during evaluation — just ask.
Compliance posture, honestly
Where we stand — and where we’re headed
- LocuPedia is designed with Canadian privacy principles (PIPEDA) and healthcare data-handling expectations in mind — minimization, consent, accountability and safeguards are built into the workflows themselves.
- Independent security assessments are part of our roadmap as we scale. We’ll announce them when they’re complete — with the results we actually received.
- Because staffing workflows carry no patient information, LocuPedia’s data surface is deliberately narrow — workforce data only, handled with the discipline healthcare expects.
LocuPedia is a young platform. Rather than decorate this page with badges we don’t hold, we describe what we do today in plain language — and answer detailed questions directly.
Security documentation is available during evaluation. Reach us via the security contact form or security@locupedia.com — a person reads every message.
Report a security concern
A vulnerability, a privacy worry, suspicious activity on your account — tell us. Every report is read by a named person, acknowledged within two business days, and tracked with a reference number until it’s resolved. Responsible disclosure is welcome and safe here.
Get started
Workforce infrastructure you can put your name behind.
Verified clinicians, two-person approvals and a complete audit record — on a platform that tells you exactly how your data is handled.
Security questions? Ask our team — or email security@locupedia.com