Skip to content

Security

Built for information you're responsible for.

Your clients trust you with their SIN, their income and their family. Here's how Heedlight keeps that trust with you.

Encrypted identifiers

SINs and business numbers are encrypted in the database with keys kept apart from the data, so a copy of the database alone doesn't reveal them.

Masked by default

Identifiers show masked everywhere. Only people you allow can reveal a full SIN, and each reveal is written to the practice's history.

Separate practices

Every record belongs to one practice, and every request is checked against it. One practice can never see another's clients.

Two-step sign-in

Staff can protect their accounts with an authenticator app, on top of their password.

A full history

Changes to clients, work and settings are recorded with who made them and when, so you can always answer "what happened here?"

Roles and permissions

Decide what each person on your team can see and change, from billing to sensitive client details.

Assistants

Assistants see only what you allow.

When your team or your clients use Heedlight from Claude, ChatGPT, Copilot or Gemini, the same rules hold, and a few more that can't be switched off.

How it works

The same permissions as the person, never more
SINs, business numbers and bank details never shown
Messages to clients confirmed before they go
Payments and signatures on your own secure pages
Every action in the audit log; disconnect in one click

Your data stays yours

Take it with you, any time.

An owner can download a full backup of the practice's records whenever they like. No lock-in, no request form.

Card payments handled by Stripe, never stored by us
Every page served over HTTPS
Staff and client accounts kept separate
A full backup, whenever an owner asks