PCIT Tracker

SECURITY OVERVIEW

Last updated July 12, 2026

This page describes how Cubic Insights LLC ("we," "us," or "our") secures PCIT Tracker, available at https://www.pcit-tracker.com(the "Services"). It is written to be specific about what we actually do. If anything here is unclear, or you need more detail for a security review, email us at admin@pcit-tracker.com and you will get a direct answer.

OUR APPROACH

PCIT Tracker is used by licensed clinicians and healthcare organizations, and the data they enter can concern child clients and their families. We treat that as the baseline threat model for every design decision, not an edge case. Our security program is designed to align with the HIPAA Security Rule, and our controls are aligned with the SOC 2 Trust Services Criteria. If you are a covered entity, see HIPAA & Business Associate Agreements for our HIPAA role and how to put a BAA in place. We do not currently hold a third-party certification or attestation; independent attestation is on our roadmap, and we would rather tell you that plainly than imply otherwise. There is no such thing as an official "HIPAA certification," and you should be skeptical of any vendor who claims one.

The product itself is built to minimize the sensitive data it holds: client records are organized around coded identifiers and labels rather than dedicated name, date-of-birth, or address fields, and we recommend that customers use initials or internal client codes instead of full names. Less identifying data stored means less to lose.

DATA PROTECTION

  • Encryption in transit. All connections to the Services are encrypted with TLS (HTTPS).
  • Encryption at rest. Customer Data is stored encrypted at rest in our database and file storage infrastructure.
  • US hosting on AWS, under a BAA. The Services run entirely on Amazon Web Services in United States regions, and we operate under a Business Associate Agreement with AWS. The database runs in a private network segment that is not reachable from the internet, and uploaded files are stored in private buckets served only through authenticated application routes.
  • Organization separation. Data is logically separated by organization, and access is scoped to the requesting user's organization: users in one organization cannot access another organization's data.
  • Role-based access. Within an organization, access is governed by roles, so administrators control who on their team can see and do what.
  • Payment data. Payments are processed by Stripe using Stripe-hosted checkout and billing pages. Card numbers never touch our servers.

APPLICATION SECURITY

  • Authentication. Sign-in is via email and password or single sign-on with Google or Microsoft. Passwords are stored hashed, never in plain text. Session cookies are httpOnly and secure.
  • Two-factor authentication. Two-factor authentication is available to all users, supporting authenticator apps (TOTP) and email one-time codes, with backup codes for recovery.
  • Audit logging. The Services maintain audit logs of significant events across account, organization, training, and clinical-record operations, including field-level tracking of edits to caregiver-completed forms and login activity.
  • Least-privilege internal access. Internal access to production systems and data is restricted to what is needed to operate and support the Services.
  • Development practices. Every change passes automated linting, type checks, and unit and end-to-end tests before deployment, and we keep third-party dependencies up to date.

AVAILABILITY AND BACKUPS

Our database performs automated daily backups with 7-day point-in-time recovery, and we maintain and periodically test recovery procedures so that we can restore service and data if something goes wrong. We monitor the Services for errors and availability issues. We do not publish uptime percentages or contractual recovery-time guarantees on this page; if your organization needs contractual availability commitments, contact us at admin@pcit-tracker.com.

You can also export your organization's family and session data from within the application at any time during your subscription, so your records are never locked in.

INCIDENT RESPONSE

We monitor the Services with error tracking and internal alerting so problems surface quickly. If we confirm a security incident affecting your data, we will notify affected customers without undue delay, consistent with applicable law and, where one is in place, the breach-notification terms of the applicable Business Associate Agreement. Notifications will describe what happened, what data was involved, and what we are doing about it.

SUBPROCESSORS

We use a small, deliberately short list of third-party service providers to run the Services, and we bind them to data-protection obligations consistent with our Privacy Policy and, where applicable, our BAAs. The current list, including what each provider does and what data it handles, is published at /subprocessors.

HIPAA

When customers who are HIPAA covered entities (or business associates) use the Services with protected health information, Cubic Insights LLC acts as a business associate, and we sign Business Associate Agreements. PHI should not be submitted to the Services until a BAA is in place. See our HIPAA & BAAs page for details, or email admin@pcit-tracker.com to request a BAA.

RESPONSIBLE DISCLOSURE

If you believe you have found a security vulnerability in the Services, please report it to admin@pcit-tracker.com with enough detail for us to reproduce the issue. We will acknowledge your report, investigate, and remediate confirmed issues promptly. We welcome good-faith security research, and we will not pursue legal action over research that meets all of the following conditions: the research is conducted solely to identify a vulnerability and report it to us; it does not access, modify, or destroy other users' data and does not degrade the Services; you give us a reasonable opportunity to remediate before any public disclosure; and you do not retain, use, or disclose any data or non-public information obtained in the course of the research.

This safe harbor applies only to good-faith security research as described above. It does not authorize competitive analysis, reverse engineering for any purpose other than identifying a vulnerability to report to us, or any use of the Services, their content, or research findings for competitive purposes, and it does not waive any of our rights under our Terms of Service or Responsible Use Policy. We do not currently operate a paid bug bounty program.

QUESTIONS

Security questionnaires, procurement reviews, and any other questions about this page can be sent to admin@pcit-tracker.com.