Plain-language summary

Security overview

AfterSession is built for sensitive coaching, counseling, and advisory conversations. We aim to communicate only the controls the product already ships today.

Tenant isolation

Professional data stays scoped to an organization through row-level security, automated tests, and org-scoped portal reads.

Transcript protection

Session transcripts use envelope encryption at rest, and the database never exposes raw transcript content through the portal.

Portal access controls

Portals are token-gated and can require email verification. Public payloads are least-data by design.

Owner controls

Owners can disable AI drafting, configure transcript retention, export organization data, and permanently reset content.

Operational hardening

AfterSession includes audit trails, config validation, rate limiting, and documented backup/DR procedures.

Boundary statement

AfterSession is currently positioned for coaching and professional guidance. It is not marketed as a clinical HIPAA records system at this stage.