Security

October 8, 2026 · Daybook Health, New York, NY

How Daybook protects the data its customers trust it with. This page states what is true today, in plain terms, and leaves out anything we have not done yet.

Business Associate Agreements

We have signed Business Associate Agreements with Cloudflare and Fly.io, the two providers that host Daybook and store its data. We sign a Business Associate Agreement with each customer before any protected health information is processed.

Encryption in transit

Every connection to the website and to the Daybook app uses HTTPS, so data is encrypted with TLS on its way between your browser and our servers.

A separate database for each customer

Each customer's data is stored in its own database, served by its own Worker, apart from every other customer's. One customer's records never share a database with another's.

Access controls

Everyone signs in with a named account of their own, and there are no shared logins. A person sees only the data of the organization whose account they belong to.

Audit logging

Daybook keeps an audit log of sign-ins and of the changes people make in the app, recording who acted, what they did and when.

Email carries no patient data

Account email, such as sign-in links, invitations and notices, is sent through Resend and never contains patient data or other protected health information.

Certifications

Daybook does not hold a third-party security certification or audit report today. When that changes, this page will say so, and not before.

Reporting a security issue

If you believe you have found a security issue in the website or the app, please write to us before sharing it anywhere else. Our Privacy Policy covers how we handle personal information.

Daybook Health · New York, NY
brian@daybook.healthcare