Security & Compliance

The bar is insurance-grade.

PineReport holds the most sensitive data your camp has: medical incidents involving minors. Here's exactly how we protect it, who has access, and where it lives.

Encryption at rest & in transit HIPAA-aligned · BAA available PIPEDA & Law 25 compliant 🍁 Canadian residency available
01 · Encryption

Encrypted everywhere, always.

Every byte of camp data is encrypted in transit and at rest. Photos and medical fields use an additional layer of envelope encryption.

PineReport uses industry-standard encryption at every layer of the stack. There is no path through the system where camp data is unencrypted.

  • In transit
    TLS 1.3 minimum on all connections. HTTP Strict Transport Security (HSTS) enforced. Certificate transparency monitoring.
  • At rest
    AES-256 encryption on all database storage and object storage. Per-tenant encryption keys for isolation between camps.
  • Photos & medical fields
    Additional envelope encryption with per-record keys. Even with database access, a record can't be read without the in-memory key released at request time.
  • Backups
    Nightly encrypted backups with point-in-time recovery for 30 days. Backup integrity verified weekly.
  • Key management
    AWS KMS with automatic 90-day key rotation. No PineReport employee has access to plaintext encryption keys.
  • 02 · Access controls

    Least privilege, by default.

    Counselors see what they create. Directors see their camp. PineReport employees see nothing without explicit, audited reason.

    Customer-facing access: Every account uses role-based access controls. Medical incident details require explicit permission and aren't visible to general staff by default. Every record view is logged in the audit trail.

    Employee access: No PineReport employee has standing access to customer data. Production access requires explicit time-bounded grants tied to a specific support ticket, approved by a second engineer, and logged in our audit system. Direct database access is restricted to two senior engineers and requires bastion VPN + hardware key + just-in-time approval.

    Authentication: SSO (SAML 2.0 + Google Workspace) on Standard and Large tiers. Multi-factor authentication required for all director and admin accounts. Session tokens rotated on every privilege escalation.

    Audit logging: Every access to a medical record is logged with timestamp, user, IP, and reason. Logs are retained for 7 years and tamper-evident (signed hash chain). Camp admins can review their full audit log at any time.

    03 · HIPAA & BAA

    HIPAA-aligned. BAA available.

    While most camps aren't HIPAA covered entities, PineReport handles medical incident data with HIPAA-aligned safeguards.

    Most summer camps fall outside HIPAA's definition of a covered entity. But the data — minor injury reports, medication notes, parent communication about medical events — has the same sensitivity. We treat it that way.

    HIPAA-aligned handling means encryption, access controls, audit logging, breach notification, and minimum necessary access — applied to medical incident fields specifically. The technical and administrative safeguards mirror what we'd implement for a covered entity.

    If your camp operates a healthcare-adjacent program (camps run by hospitals, camps for campers with chronic conditions, day programs reimbursed by insurance) you may need a Business Associate Agreement (BAA). We have one ready and execute it as part of customer onboarding at no extra cost.

    Available Business Associate Agreement (BAA)

    Reviewed by camp insurance counsel; available on request during onboarding. Required for any camp where the workflow touches HIPAA-covered records.

    04 · Privacy laws

    Built for the laws
    your camp operates under.

    From CCPA to PIPEDA to Quebec's Law 25 — PineReport meets your jurisdiction's privacy requirements, including the strict ones.

    United States. PineReport complies with state privacy laws including CCPA/CPRA (California), Texas, Colorado, Connecticut, and Virginia. We do not sell or share personal information for any purpose. State-specific data subject rights (access, deletion, portability) are supported through your camp's admin dashboard.

    Children's privacy (COPPA). PineReport is not a child-directed service. Campers do not interact with the product, do not have accounts, and do not provide information directly. Counselors log records about campers, analogous to a school records system. The data controller is the camp, with parent consent obtained at registration.

    Canada — PIPEDA. Federal compliance with all ten fair information principles. Designated privacy officer at PineReport Inc. Privacy impact assessments documented for major product changes.

    Quebec — Law 25. Fully supported. Privacy impact assessments on file. Cross-border transfer impact assessments documented. 72-hour breach notification commitment. French-language consent templates and customer agreement available.

    Alberta & British Columbia — PIPA. Provincial breach notification thresholds tracked. Compliance documented in our DPA.

    Parent consent. Your camp remains the data controller; PineReport is the processor. We provide a ready-to-use consent paragraph (English and French) for your registration paperwork. Parents direct access requests to your camp; you fulfill them using PineReport's admin tools.

    05 · Data residency

    Your data lives where you choose.

    Tenant-level region pinning, set at provisioning. Customer data does not leave the region.

    Region selection is a tenant-level configuration baked into our architecture, not a retrofit. When a camp signs up, you choose your region — your data, including backups and processing, stays there.

  • 🇺🇸 United States
    OVH Cloud (Beauharnois, QC) — Canadian data residency available by default. US camps can request US-region hosting.
  • 🇨🇦 Canada
    OVH Cloud (Beauharnois, QC). Data does not cross the US border. Suitable for municipal camps and Quebec camps under Law 25.
  • Cross-border policy
    Data assigned to a region stays in that region. Backups, replicas, and processing all happen in-region. No data leaves the region except for explicit customer exports.
  • Why this matters in Canada
    The US CLOUD Act lets US authorities compel data disclosure regardless of physical location, if held by a US company. Canadian residency is offered both for legal compliance (Law 25) and to reduce CLOUD Act exposure for sensitive Canadian camp data.
  • 06 · Sub-processors

    The full list, kept current.

    Every third-party service we use to deliver PineReport. Updated when anything changes; notification sent to customers 30 days in advance.

    A sub-processor is a third party that touches customer data on our behalf. We keep the list short on purpose; every addition has to clear a security review.

    SUB-PROCESSOR PURPOSE REGION
    Amazon Web Services Infrastructure, database, object storage us-east-1 / ca-central-1
    Cloudflare CDN, DDoS protection, edge caching Global edge / no PII cached
    Postmark Transactional email (notifications, alerts) US
    Twilio SMS alerts for on-call directors US / global SMS routing
    Stripe Payment processing (no PII shared) US / Canada
    Sentry Error monitoring (PII scrubbed) US

    Notification policy: Customers get 30 days' advance notice for new sub-processors. Critical changes (region, vendor replacement) are communicated by email to the camp admin and posted to status.pinerecord.com.

    07 · Certifications

    Independently verified.

    Where we are on the certification roadmap. Audit reports available under NDA for prospective customers.

    08 · Incident response

    When something goes wrong, you'll hear it from us first.

    Our incident response process, breach notification commitments, and where to report a vulnerability.

    24/7 monitoring. Automated alerts on security anomalies, including unusual access patterns, failed authentication spikes, and infrastructure changes outside expected windows.

    Incident response team. A trained on-call engineer is reachable within 15 minutes for any priority-1 incident. Severity classification is automated; engineering leadership is paged for any incident that may involve customer data.

    Breach notification commitments:

  • Customer notification
    Within 24 hours of confirmed breach involving your data, regardless of jurisdiction. Notification goes to the camp admin email and includes scope, timeline, and remediation steps.
  • Quebec / Law 25
    72-hour notification to the Commission d'accès à l'information du Québec and affected camps, per Law 25 requirements.
  • PIPEDA
    "Real risk of significant harm" breaches reported to the Office of the Privacy Commissioner of Canada and affected individuals.
  • US state laws
    Notification per applicable state law (California, Texas, NY, etc.), with the strictest timeline taking precedence.
  • Report a vulnerability. Email security@pinerecord.com. We acknowledge reports within 24 hours and credit responsible disclosure researchers in our security hall of fame.

    For your procurement review.

    Everything your IT, legal, or insurance team needs. Most documents available immediately; a few require an NDA.

    📄

    Standard DPA

    Data Processing Agreement covering subprocessors, breach notification, retention, audit rights. US and Canadian versions.

    Download PDF →
    📄

    BAA template

    Business Associate Agreement template for HIPAA-adjacent camps. Negotiable; we'll work with your counsel.

    Request template →
    📊

    Privacy policy + ToS

    Standard public documents. US and Canadian versions. French version available for Quebec camps under Bill 96.

    View documents →
    📬

    Talk to security team

    Have a specific question or compliance requirement? We'll get the right engineer or counsel on a call within 48 hours.

    Contact security →