Security & trust
Handled with the same rigor as a paper chart — just harder to lose
Client and caregiver data is real health-adjacent information. It's treated that way at every layer, not bolted on after the fact.
How it's protected
Four real safeguards, not marketing filler
Nothing here is a generic "bank-level encryption" claim — each of these maps to how the app is actually built.
Role-based access
Agency admins, caregivers, family observers, and GOAT staff each see only what their role is meant to see — enforced at the database level, not just hidden in the interface.
Family access is read-only
Observers set up by the agency can view a client's real progress. They can't edit a record, change a plan, or export raw data.
Your data stays your agency's
One agency's clients, caregivers, and outcomes are never visible to another agency — including on ActiveCare's own GOAT-staff side.
Never sold, never shared
Client and caregiver data is never sold or shared with third parties. It leaves the system only when your agency chooses to export or deliver a report.
Enforced where it can't be bypassed
Access rules live in the database's row-level security policies, not just in app-layer checks — so even a bug in the interface can't leak one agency's data into another's view.
Questions about how your data is handled?
Get a walkthrough with your own agency's setup in mind.