Trust & Security

What we actually do with your data

Stated in plain language, including the parts that aren’t finished yet. A trust page that only lists what’s already good isn’t one you should trust.

How your uploaded documents are handled

When you upload a credential, the file is read by an AI model to extract the expiration date, certificate number, issuer, and a short title -- so you don’t have to retype them. Today that extraction runs on Google’s Gemini API using a standard consumer key, not a HIPAA-eligible configuration.

We’re stating that plainly rather than implying otherwise: if your organization’s credential data is subject to HIPAA, this is a real, open gap, and it’s tracked as one internally. Resolving it means migrating extraction to a BAA-covered path (e.g. Vertex AI under a signed Google Cloud Business Associate Agreement) -- a deliberate infrastructure change, not something to quietly claim is already handled. Ask us for current status before treating this as resolved.

Identity verification

When you verify your identity in Settings, the actual government-ID check happens entirely on Stripe’s side. Emerpa never sees your ID document or the biometric match -- Stripe tells us only whether verification passed, failed, or needs more input.

The audit log is append-only

Role changes, membership removals, credential verifications, and every other logged compliance action are written once and never edited or deleted afterward -- including by us. There is no update or delete path on this table at all, at the database level. If your organization is ever asked to produce a record of who did what and when, this is designed to be something you can actually rely on.

Primary Source Verification

Where a credential type has a real public registry (state nursing boards via Nursys, ServSafe, NMLS, CPAverify, DocInfo, NIPR, and others), Emerpa links directly to that registry’s own official lookup page and records when a person confirmed their credential matches it. This is a manual confirmation against the primary source, not an automated database cross-reference -- we say so in the product, not just here, because the distinction matters.

For credential types with no single national registry (contractor and attorney licenses, for example, which are regulated per-state), Emerpa says that honestly rather than pointing you at a link that won’t actually have your record.

Platform admin access is logged and visible

A small, separate table -- distinct from any organization’s own manager/employee roles -- controls who has platform-level administrative access. Every admin action (plan changes, account-level overrides) is written to its own permanent, append-only log, and the current list of who holds admin access is itself visible to other admins, not hidden.

Questions about any of this? Reach out.