Security & privacy

Trust is our product’s foundation

Healthcare workforce data — credentials, documents, schedules, payment records — deserves disciplined handling. Here is exactly how LocuPedia handles it: what we do, what we never do, and what we’re still working toward. No borrowed badges, no vague promises.

Our security principles

Four rules every decision answers to

These aren’t aspirations on a policy page — they’re the principles the product is built around, visible in how LocuPedia actually works.

01

Data minimization

We collect the workforce data a staffing workflow needs — and nothing beyond it. Patient information is never part of any LocuPedia workflow, and we don’t gather personal data “just in case.” Less data held means less data at risk.

Fields our forms don’t have — by design
patient nameshealth card numbersdiagnosesvisit noteslab results“nice to have” analytics

Not hidden behind a permission, not restricted to staff — never collected. You cannot leak a field that doesn’t exist.

02

Least-privilege access

Every account sees only what its role requires — a department coordinator doesn’t see another department’s requests, and an organization never sees a clinician’s documents without an active opportunity between them. Access is scoped by default, not by request.

Pick a role — see exactly what it can see
03

Accountability by default

Every action on the platform is attributable to a named individual and written to a reviewable audit record — who viewed, posted, applied, changed or closed what, and when. When something matters, you can always answer “who did this?”

Live illustration — every action, a named person, a timestamp

    The clinician sees these entries too — being watched works both directions here.

    04

    Honesty over marketing

    We publish only what we do today. Where practice is still maturing — independent assessments, formal certifications — we say so plainly and tell you what’s on the roadmap, rather than borrowing credibility we haven’t earned.

    Said plainly, with dates
    • Encryption in transit & at rest, scoped roles, audit history Live today
    • Independent security assessment On the roadmap
    • Formal certification — announced only with results in hand On the roadmap
    • Displaying badges we haven’t earned Never

    This page is re-read and dated with every change — last reviewed October 2026. Changes to these rules appear here before they take effect.

    We are not here to make a business out of your data. We are here so no clinic goes uncovered and no clinician is treated like inventory — and nothing you entrust to LocuPedia is for sale, rent or trade, to anyone, ever. Security isn’t our sales pitch; it’s the condition for being allowed to work in healthcare at all.

    The promise every LocuPedia decision answers to — an eSora Labs company

    How we protect data

    The controls behind the promise

    Six concrete layers, described in plain language. If you’re evaluating LocuPedia for your organization, this is the level of specificity you should expect from any vendor.

    Encryption in transit

    Every connection between your browser and LocuPedia is encrypted with modern TLS — including every credential document upload and download.

    • TLS on every connection, no exceptions
    • Documents travel encrypted end to end

    Encryption at rest

    Stored data — profiles, credential documents, requests, records — is encrypted at rest, so information stays protected even where it lives.

    • Databases and document storage encrypted
    • Backups covered by the same standard

    Access controls & permissions

    Role-based permissions scope what each user can see and do — by facility, department and responsibility. Clinicians control the visibility of their own profiles.

    • Roles for coordinators, reviewers, finance, admins
    • Clinician-controlled profile visibility

    Authentication & account security

    Every user has an individual account — no shared logins — protected by a password policy and managed sessions, so access is personal and revocable.

    • Individual accounts, always attributable
    • Session management and sign-out controls

    Bounded document sharing

    Credential documents are visible only to the organization reviewing that specific opportunity — and only while the opportunity is active. Nothing is broadcast.

    • Sharing tied to a real, active opportunity
    • Access ends when the opportunity closes

    Audit history

    Requests, approvals, messages and changes are logged with the person and timestamp attached — a reviewable history of who did what, and when.

    • Every decision attached to a named person
    • Exportable for your own records and reviews

    Clear boundaries

    What we never do

    Some commitments are easier to keep as absolutes. These are ours — held as product rules, not marketing lines.

    • No patient information in staffing workflowsStaffing data and patient data are different worlds. LocuPedia stays in its own — patient information is not collected, not stored, not asked for.
    • No selling or sharing personal data with advertisersProfiles and credential records exist to place clinicians in work they choose — nothing else, for anyone else.
    • No displaying certifications or badges we haven’t earnedNo borrowed seals, no aspirational logos. When we earn a certification, you’ll see it here — not before.
    • No access to your profile without your participationOrganizations see a clinician’s profile only through an opportunity the clinician is connected to. There is no silent browsing.
    • No keeping data beyond its purposeRetention is bounded. When you delete your account, or a record reaches the end of its purpose, it is purged — except the minimum audit records the law requires, which we’ll list for you on request.
    • No quiet changes to these rulesThese commitments change only in public: any change is posted on this page, with its effective date, before it takes effect — never buried in an update email.

    How these stay true: they’re written into product requirements, not a policy PDF — a feature that breaks one of these rules does not ship, whoever asks for it. If you ever catch us near the line, report it below — that report lands with a named person, not a queue.

    Your data rights

    Your data stays yours

    Both sides of the platform hold real, exercisable rights over their information — no tickets into a void, no fine print. Don’t take the sentence on faith: try the controls below.

    Try it — your controls are real

    Flip the switches. Watch what an organization sees.

    Every clinician holds these switches from day one. Flip them and watch the organization’s view change on the right — this isn’t a promise about policy, it’s how the product behaves.

    What Riverside Family Clinic seesupdates live

    For clinicians

    Your profile, credentials and work history belong to you.

    • View and export your data. See everything on your record and take a copy with you, whenever you want.
    • Control your visibility. You decide which opportunities connect you to an organization — your profile is never public.
    • Request deletion. Ask for your account and personal data to be deleted, subject only to records we’re required to keep.

    For organizations

    Your requests, decisions and records are yours to keep and audit.

    • Export your records. Requests, approvals and audit history export for your own compliance and review processes.
    • Control team access. Add, change or revoke roles as people join, move and leave — access follows responsibility.
    • Ask us anything. Security documentation is available during evaluation — just ask.

    Compliance posture, honestly

    Where we stand — and where we’re headed

    • LocuPedia is designed with Canadian privacy principles (PIPEDA) and healthcare data-handling expectations in mind — minimization, consent, accountability and safeguards are built into the workflows themselves.
    • Independent security assessments are part of our roadmap as we scale. We’ll announce them when they’re complete — with the results we actually received.
    • Because staffing workflows carry no patient information, LocuPedia’s data surface is deliberately narrow — workforce data only, handled with the discipline healthcare expects.
    We will never claim a certification before it’s earned

    LocuPedia is a young platform. Rather than decorate this page with badges we don’t hold, we describe what we do today in plain language — and answer detailed questions directly.

    Security documentation is available during evaluation. Reach us via the security contact form or security@locupedia.com — a person reads every message.

    Report a security concern

    Found something? Report a concern.

    A vulnerability, a privacy worry, suspicious activity on your account — tell us. Every report is read by a named person, acknowledged within two business days, and tracked with a reference number until it’s resolved. Responsible disclosure is welcome and safe here.

    Get started

    Workforce infrastructure you can put your name behind.

    Verified clinicians, two-person approvals and a complete audit record — on a platform that tells you exactly how your data is handled.

    Security questions? Ask our team — or email security@locupedia.com