Legal

Security & Compliance

What we do to protect your household's information, the notices you can expect from us, and how to report a problem.

Last updated: August 12, 2026

Access control

Every record in ERIKA belongs to exactly one account. Database-level row security rules enforce that ownership on every read and write, so one account cannot reach another account's profiles, plans, appointments, providers, or insurance records — even if the application layer is bypassed.

Administrative access is limited to named staff accounts with an explicit role, and administrative actions are written to an audit log.

Data protection

  • All traffic between your browser and ERIKA is encrypted in transit with HTTPS.
  • Data is stored with our managed hosting provider, which encrypts data at rest.
  • Uploaded insurance cards and documents are kept in private storage and are only reachable through short-lived signed links generated for your account.
  • Passwords are handled by our authentication provider and are never stored by us in readable form.

Notifications you can expect

These are the notices ERIKA sends. You can change reminder preferences in Account settings; service and security notices cannot be turned off because they concern your account.

  • Care reminders — when a plan item becomes due or an appointment is coming up. Optional.
  • Insurance expiry notices — when a policy you have recorded is within 60 days of its expiry date. Optional.
  • Account and security notices — sign-in from a new device, password or email changes, and account closure confirmations. Always sent.
  • Policy change notices — advance notice before material changes to the privacy notice or terms take effect. Always sent.
  • Incident notices — if a security incident affects your information, we will tell you what happened, what data was involved, and what to do, within the time your local law requires.

Your responsibilities

  • Use a strong, unique password and keep it private.
  • Sign out on shared devices.
  • Only upload documents you have the right to store.
  • Tell us promptly if you think your account has been accessed by someone else.

Scope of our commitments

ERIKA is a consumer planning tool. We describe here only the controls we actually operate. We do not claim any certification, audit outcome, or regulatory compliance status on this page. If you need a formal statement about a specific framework for your organization, contact us and we will tell you plainly what we can and cannot provide.

Reporting a vulnerability

If you believe you have found a security issue, tell us through the contact form and mark the message as a security report. Please include the steps to reproduce it, and give us a reasonable window to fix it before disclosing it publicly. Do not access, modify, or delete data that is not yours while testing, and do not run automated scans that degrade the service for other users. We will acknowledge your report and keep you updated until it is resolved.