The platforms we build house some of the most sensitive data a family shares with anyone: their child's records. We apply enterprise-grade security practices to every deployment.
Infrastructure Security
We deploy on established cloud infrastructure providers that maintain SOC 2 Type II and ISO 27001 compliance. All data at rest is encrypted with AES-256, and all data in transit is protected with TLS 1.3.
Application Security
- Authentication: Hardened session management with support for multi-factor authentication on staff and admin accounts.
- Access control: Role-based permissions ensure a parent, staff member, or administrator can only view records their role is authorized to access.
- Child data minimization: Photos and daily reports are scoped to authorized family contacts only, never publicly accessible.
- Audit logging: Key actions on enrollment, ratio, and billing records are logged for review.
Payment Security
EMM2 does not store credit card numbers on our own servers. All payment processing is handled through PCI-DSS Level 1 certified providers.
Vulnerability Reporting
If you believe you've found a security vulnerability in our systems or in a platform we've deployed for a client, please email security@emm2llc.us. We respond to all reports within 48 hours.