Trust

Security, in plain language

Health and safety records name real people on their worst days. Here is how FreeHS treats them — in the same plain terms the rest of the site uses, including the part most security pages leave out: what we don't have yet.

One organisation, one boundary

Every record belongs to your organisation and is scoped to it at the data layer. A workspace can never read another workspace — isolation is how the platform is built, not a filter applied on top.

Permissions enforced on the server

Named permission sets govern who can see and do what, and every check runs on the server — hiding a button is never the security model. Deactivating a person takes effect immediately, including sessions already signed in, and the platform refuses any change that would leave a workspace without an administrator.

Sign-in without passwords

Sign-in is a one-time code sent to a verified email address. There is no password to phish, reuse or leak in someone else’s breach — and nothing for your team to write on a post-it.

Confidential records stay confidential

Sensitive incident kinds — sharps, violence & aggression — are confidential by default: counted in every statistic, readable only by the people who should. That confidentiality is enforced everywhere the data could surface, including search, exports and the AI assistant.

Share links you control

Public share links — inspection reports, RAMS packs, briefings — use long, unguessable tokens, are excluded from search-engine indexing, and can be revoked at any moment. Revocation is immediate.

The assistant sees what you see

The AI assistant answers only from your own workspace’s records, filtered by your own permissions. On WhatsApp, every inbound message is signature-verified and the sender is matched to their account before anything is looked up.

Telemetry without your data

Error reporting is scrubbed before it leaves the application: request bodies, cookies, query strings and access tokens are stripped, so diagnosing a fault never means exporting your records.

Encryption, backups and audit

All traffic is encrypted in transit, and the application runs on managed cloud infrastructure. Pro workspaces add daily backups. Administrative activity is recorded in an audit log your administrators can review from settings, and every register exports on demand — your records are never held hostage.

What we don’t have yet

We would rather tell you than have you discover it: single sign-on (SSO/SAML) and formal certifications such as ISO 27001 are not yet in place. If your organisation needs a security questionnaire answered before adopting, send it over — we answer them honestly.

Questions, questionnaires, disclosures

All of it goes to support@freehs.software. If you believe you have found a vulnerability, please report it there before disclosing it anywhere else — we take reports seriously and reply like humans.