Security
The safest patient data is the data we never hold.
This page describes controls that are implemented today, in plain language. It is not a certification, and no page can prove the absence of all defects.
No patient information, by design
Shift schedules staff, not patients. There are no patient fields anywhere in the product — no names, no record numbers, no clinical detail. The riskiest category of healthcare data is absent structurally, not filtered.
Workspace isolation at the database
Every table is protected by row-level security scoped to your workspace. One department's roster, schedule, and requests are invisible to every other workspace — enforced by the database itself, not just the application.
Sign-in and sessions
Authentication runs on Supabase Auth over TLS. Sessions are cookie-based and every request re-checks membership; removing someone from the workspace cuts their access on their very next request.
Two-step verification
Any account can add a six-digit code from an authenticator app, and from then on sign-in asks for it before any page or request answers. A workspace can require it of everybody, with a seven-day window for people to set it up; the requirement is off until an administrator turns it on, and turning it off is recorded as plainly as turning it on. If the check cannot be completed, the request is refused rather than allowed through.
Browser hardening
Every response carries the headers that stop the page being framed, sniffed, or leaked through a referrer, denies camera, microphone and location outright, and pins the browser to HTTPS. A content-security policy holds the app to its own origin plus the database it talks to, and is checked against every real screen so it cannot quietly break the product.
Roles that mean something
Owners and managers configure and publish; techs see their own schedule, volunteer, swap, and request time off. Write paths check the role on the server — hiding a button is never the security boundary.
Revocable feed tokens
Calendar feeds and the OrderFlow roster import use long, unguessable per-scope tokens. Each serves the minimum data its purpose needs, and disabling or regenerating a token kills the old link immediately.
Governed change, not silent change
Schedule-affecting actions record who did them. The draft engine proposes and a human decides — nothing publishes a schedule, books a person, or changes coverage on its own.
Checked, and honest about what is not
Workspace isolation, role boundaries and the private columns are exercised by automated tests that try to break them from a real signed-in account, and dependencies are audited. Axiom Shift holds no penetration test, no SOC 2 report and no other certification, and says so rather than implying otherwise.
What this is not
- Axiom Shift is built to hold workforce data, not patient data. Whether a Business Associate Agreement is required is your organization’s determination to make, not ours. Raise it during procurement and we will work to your compliance team’s answer.
- We do not hold SOC 2, HITRUST, or ISO certifications and do not imply otherwise. Ask us anything specific — you will get a direct answer about what is and is not in place.
- Staff names, credentials, and work schedules are still workforce data and are treated with the isolation and access controls described above.
Security questions during procurement: info@axiomeeg.com
