Security & Compliance
Maintained by the Accrue ABA team
This page is maintained by the Accrue ABA team and describes controls that are enabled in the product today. It is not an independent audit, a certification, or a guarantee. Security is shared: we operate the platform, your organization operates its accounts, staff, and policies.
Access control
- Every record belongs to exactly one organization, enforced at the database level.
- Roles: administrator, BCBA supervisor, trainee, and RBT, each with a different scope.
- Care teams and supervision assignments narrow access to specific students and trainees.
- Internal permission helper functions are not reachable from the public API surface.
Authentication
Email and password sign-in with leaked-password checking, plus Google sign-in. Sessions time out after a period of inactivity that organization administrators can shorten, and signing out clears cached data in the browser.
Audit logging
Views of student records, edits, signatures, exports, invitations, and consent changes are written to an append-only audit log scoped to your organization. Administrators can search and review it from organization settings. Application users cannot edit or delete audit entries.
Data protection
Data is encrypted in transit and at rest by the hosting platform, and backups are managed by the platform. Service credentials are stored as managed secrets and are never exposed to the browser.
HIPAA-conscious operation
Accrue is designed to operate with minimal protected health information: initials instead of names, optional demographic fields, and an organization-wide minimal-PHI mode. Covered entities that need a business associate agreement can record and download it from the organization settings screen before entering protected health information. Do not enter PHI beyond what your program requires.
Children's data
Guardian consent is tracked per student and surfaced to staff and administrators. See the children's privacy page for details.
Subprocessors and school use
Our current subprocessor list is on the Subprocessors page. School and district customers can review our Schools & FERPA page for how Accrue acts as a school official under FERPA.
Reporting a security issue
If you believe you have found a vulnerability or a data exposure, stop testing and contact your organization administrator, who can reach our team through the support channel in organization settings. We investigate all reports and will confirm receipt.