Plain-language summary
Security overview
AfterSession is built for sensitive coaching, counseling, and advisory conversations. We aim to communicate only the controls the product already ships today.
Tenant isolation
Professional data stays scoped to an organization through row-level security, automated tests, and org-scoped portal reads.
Transcript protection
Session transcripts use envelope encryption at rest, and the database never exposes raw transcript content through the portal.
Portal access controls
Portals are token-gated and can require email verification. Public payloads are least-data by design.
Owner controls
Owners can disable AI drafting, configure transcript retention, export organization data, and permanently reset content.
Operational hardening
AfterSession includes audit trails, config validation, rate limiting, and documented backup/DR procedures.
Boundary statement
AfterSession is currently positioned for coaching and professional guidance. It is not marketed as a clinical HIPAA records system at this stage.
