Security
How Daybook protects the data its customers trust it with. This page states what is true today, in plain terms, and leaves out anything we have not done yet.
Business Associate Agreements
We have signed Business Associate Agreements with Cloudflare and Fly.io, the two providers that host Daybook and store its data. We sign a Business Associate Agreement with each customer before any protected health information is processed.
Encryption in transit
Every connection to the website and to the Daybook app uses HTTPS, so data is encrypted with TLS on its way between your browser and our servers.
A separate database for each customer
Each customer's data is stored in its own database, served by its own Worker, apart from every other customer's. One customer's records never share a database with another's.
Access controls
Everyone signs in with a named account of their own, and there are no shared logins. A person sees only the data of the organization whose account they belong to.
Audit logging
Daybook keeps an audit log of sign-ins and of the changes people make in the app, recording who acted, what they did and when.
Email carries no patient data
Account email, such as sign-in links, invitations and notices, is sent through Resend and never contains patient data or other protected health information.
Certifications
Daybook does not hold a third-party security certification or audit report today. When that changes, this page will say so, and not before.
Reporting a security issue
If you believe you have found a security issue in the website or the app, please write to us before sharing it anywhere else. Our Privacy Policy covers how we handle personal information.
Daybook Health · New York, NY
brian@daybook.healthcare