Individual-Led Sharing
New cards start private. Each person chooses the audience and meaningful scope of the information they share.
Trust is the combination of individual control, carefully bounded access, resilient systems, and accountable operations.
A personal relationship, a care assignment, an organization role, and a paid subscription have different meanings. Connected Care keeps those meanings distinct.
New cards start private. Each person chooses the audience and meaningful scope of the information they share.
Assigned care personnel work within a specific organization and the client’s reviewed access, not a universal staff view.
Optional customer MFA, verified recovery, devices and session management, and explicit privacy controls support individual access.
Our architecture separates public presentation, authenticated application access, background services, and internal operations. A clearer boundary makes each responsibility easier to protect and reason about.
Current identity, relationships, role, assignment, and sharing scope govern access at the service boundary, not a hidden button in the browser.
Encryption, least-privilege access, isolated environments, and minimum-necessary operational data underpin our security approach.
Interactive sign-in and authorized background services have distinct lifecycles. Reauthentication is not the same as intentionally signing out a device.
Retry-safe actions preserve identity and history. Requested, accepted, delivered, and completed are not interchangeable states.
Technical telemetry, incident follow-through, reviewed changes, and restricted staff roles support the service. Technical success is not a human care outcome.
Reviewed source, reproducible artifacts, focused validation, and controlled release and rollback keep change accountable.
Serenity Link’s regulated-health approach combines technical safeguards with operating controls and agreements. Applicable HIPAA obligations and business-associate arrangements are reviewed for the particular service and customer relationship. A label is not a substitute for that work.
Our internal workspace separates organization administration, customer assistance, technical operations, and sensitive-data authority. Customer organizations work in Connected Care, not in this staff console.
Staff assist with accounts, relationships, invitations, and assignments using the customer’s verified instruction, not impersonation.
Application permissions accumulate through assigned roles. Highly restricted Super Admin access is not clinical-content access by default.
Aggregate operational views support awareness without putting customer identities or health information on an observation wall.
Connected Care does not diagnose conditions, recommend treatment, guarantee detection, continuously monitor every device, or guarantee that a responder answers. Source and location availability depend on real-world device, permission, and connectivity conditions.