Institutional Trust Markers
Institutional buyers in senior housing & care evaluate software the way they evaluate borrowers — on governance, audit posture, and operational discipline. SeniorCRE publishes trust markers, current assurance status, and limits honestly.
Security and compliance posture
HIPAA-aligned architecture, encryption at rest and in transit, MFA, session governance, and immutable audit logging. SeniorCRE does not claim SOC 2 certification or its own SOC 2 report.
Multi-tenant governance
33-role RBAC, hierarchical access from Holding Co to Unit, tenant isolation enforced at the database layer via row-level security and SECURITY DEFINER helpers, and a 300-function security surface tested with pgTAP.
Frequently asked questions
- How is PHI separated from non-PHI?
- PHI lives in dedicated private buckets (resident-photos, staff-photos, family-communications, resident-documents, therapy-photos) and is accessed only via signed URLs scoped under 60 minutes. Non-PHI marketing and listing assets live in public buckets and are never co-mingled.
- How are roles and permissions enforced?
- Role-based access control with a documented role hierarchy is enforced at the database, scoped by property, and audited. Permissions are auditable and revocable per role.
- What standards do you interoperate with?
- Generic HL7 v2 inbound is built. Vendor-specific connectors for PointClickCare, MatrixCare, Yardi, MRI, and NetSuite are on the design-partner / 2027 roadmap, as are full FHIR R4 exchange and bi-directional payer/provider flows. SAML 2.0 / OIDC SSO and SFTP/S3 export are supported. A published machine-readable access specification covers agent tool calling (post-pilot roadmap).
- How does SeniorCRE scale across many properties and states?
- A Holding Co → Operator → Region → Property → Unit hierarchy with property-level tenant isolation allows multi-state, multi-payer, multi-entity ownership to preserve source authority and lineage across accepted records. Portfolio rollups, covenant evidence, and ESG metrics are target-state outputs after approved sources support them.
- How do you deploy?
- Deployment timing is gate-based: scope, source access, security review, reconciliation rules, clinical-safety review where applicable, and operator acceptance. No completed operator-production deployment, fixed go-live duration, or operator-production deployment is claimed.
https://seniorcre.com/institutional-trust