Our Approach
At Ease Parent is built with a security-first mindset. We understand that families trust us with sensitive information about their children, caregivers, and daily routines. We take that seriously.
Encryption
All data is encrypted in transit using TLS 1.2+. Data at rest is encrypted using AES-256. This applies to all household data, child profiles, caregiver records, and AI conversation history.
Authentication
Accounts are protected by secure email/password authentication. Premium Parent Admin accounts have access to two-factor authentication (2FA). We recommend enabling 2FA on any account with access to medical notes or purchase approval.
Role-Based Access
Each household member has a role with scoped permissions. Nannies cannot see medical notes by default. Purchase approvals require Parent Admin authorization. These controls are enforced at the server level, not just the UI.
Integration Token Security
When you connect third-party services (e.g. shopping integrations), OAuth tokens are stored encrypted and never exposed in the client. Tokens are scoped to the minimum permissions required.
AI & Cora Security
Conversations with Cora are processed by secure AI infrastructure. Cora does not retain conversation history between sessions unless you explicitly save a note. Auto-purchase actions require explicit pre-authorization and are logged for audit.
Reporting Issues
Found a security vulnerability? Please report it responsibly at security@ateaseparent.com. We aim to respond within 48 hours.