Account protection
Role-based access, protected routes, and secure authentication flows for clinicians, facilities, and administrators.
Security is not a footer email link. This page explains how Covecare thinks about trust, access, privacy, credential protection, and responsible vulnerability reporting.
Report a security concernHealthcare staffing touches identities, credentials, payments, shifts, and facility data. The product should protect each area intentionally.
Role-based access, protected routes, and secure authentication flows for clinicians, facilities, and administrators.
Credential records, identity information, and facility approval workflows are handled with access control in mind.
Sensitive operational data should only be available to the right user, team, or facility workspace.
Key operational actions should be tracked so support, finance, and compliance teams can investigate issues clearly.
Send enough detail for the team to reproduce and investigate the issue. Do not access, modify, download, or share data that does not belong to you.
Account email, affected page, steps to reproduce, screenshots if available, browser/device, and the impact you believe the issue may have.
This creates a real page experience for security reporting. The next production step is to connect it to your support/security ticket table.