Security and data practices
This page describes how Blue Harbor Supply LLC handles customer data across its products. It is intended for administrators, licensing agencies, and procurement reviewers.
Hosting and data location
Our applications are hosted on Vercel and our databases are hosted on Neon, both in United States regions. We do not operate our own physical servers.
Encryption
All traffic between users and our applications is encrypted in transit using TLS. Data stored in our databases and file storage is encrypted at rest by our infrastructure providers. Passwords are stored as one-way hashes and are never recoverable in plain text.
Tenant isolation and access
Each customer organization is a separate tenant. Application queries are scoped to the requesting organization so that one customer cannot access another customer's records. Staff and parent accounts have separate authentication and separate permission sets.
Administrative access to production systems is limited to company personnel who require it, protected by multi-factor authentication, and used only for support, maintenance, and incident response.
Payments
Payment card data is handled entirely by Stripe, a PCI DSS Level 1 service provider. Blue Harbor Supply LLC does not store, process, or transmit full payment card numbers on its own systems.
Backups and continuity
Databases are backed up continuously by our database provider with point-in-time recovery available. Application code is version controlled and redeployable.
Data retention and deletion
Customer data is retained for as long as the account is active. Attendance records are retained so that customers can satisfy their own record-keeping obligations. On written request from an authorized administrator, we will export a customer's data and delete it from production systems. Residual copies in encrypted backups age out on the backup retention schedule.
Incident response
If we become aware of a security incident affecting customer data, we will investigate, take steps to contain it, and notify affected customer administrators without undue delay, including what we know about the scope and what action is required from them.
Scope
Our products are not designed to store protected health information under HIPAA, and Blue Harbor Supply LLC does not enter into Business Associate Agreements. Customers should not upload clinical or medical-record material to our platforms.
Subprocessors
We use the following third-party providers to deliver our services.
| Provider | Purpose |
|---|---|
| Vercel Inc. | Application hosting and content delivery |
| Neon Inc. | Managed PostgreSQL database hosting |
| Stripe, Inc. | Payment processing and payout handling |
| Resend (Plus Five Five, Inc.) | Transactional email delivery |
Security questionnaires, data processing agreements, and additional documentation are handled directly. Write to info@blueharborsupplyllc.com.