Families and law firms trust CoParent.Help with sensitive records. Here is a plain-English summary of the practices that keep that information safe. We keep this page honest — it describes what we actually do, and nothing we don't.
Encryption in transit and at rest
All traffic to CoParent.Help is served over HTTPS (TLS), with HSTS enforced so browsers refuse to connect any other way. Your data is stored on managed cloud infrastructure that encrypts it at rest.
Role-based access control
For law firms and organizations, every staff member is assigned a specific role. What each person can see and do is checked on the server for every request — not just hidden in the interface — so access always matches the role you granted.
Tenant isolation
Each firm and each family's records are scoped to their own account. Server-side checks tie every query to the signed-in user's membership, so one organization can never read another's data.
Audit logging
Sensitive actions inside a firm — inviting staff, changing roles, accessing or exporting matter records — are written to an audit log, so an organization can review who did what and when.
Rate-limited authentication
Sign-in, account recovery, and email sending are rate-limited to slow down automated abuse and credential-guessing, protecting your account and keeping notifications from being used to spam.
We never sell your data
We do not sell your personal information, and we never sell or share the contents of your messages, documents, or records. Your data is used to provide the service to you — nothing more.
An honest note on certifications
We do not currently hold a SOC 2 report or other formal security certification, and we will never claim one we don't have. If that changes, we'll say so here. In the meantime, if your organization needs specific security documentation, please reach out and we'll share what we can.
Report a concern
Found a security issue, or have a question about how your data is handled? We want to hear from you.
smithappsupport@gmail.com