Compliance
The federal frameworks our products operate within, and the safeguards we ship by default.
Frameworks we work within
Our case-management products are designed for organizations operating under one or more of the following frameworks. We ship the data structures, field requirements, deadline tracking, and audit trails to support compliance — not just box-checking.
- ORR (Office of Refugee Resettlement) — 30 / 90 / 180-day refugee benefits clocks, USCIS form management (I-485, I-765, others), case-file documentation
- HUD coordinated entry — VI-SPDAT scoring, entry/exit tracking, prior living situation, bed inventory by housing type
- VA claims — DD-214 management, claim status progression, advocate assignment, disability rating tracking
- VAWA (Violence Against Women Act) — record-sealing for DV survivors, with the system enforcing the seal across reports and exports
- State DV regulations — configurable to state-specific confidentiality requirements
- 38 CFR 21.1 — veteran benefits eligibility tracking
Safeguards we ship by default
- Row-level security tied to caseworker assignment
- VAWA-Safe seal — a DV-survivor flag that removes records from standard reports and dashboards
- ICE-Firewall — a refugee-record flag that blocks data export entirely
- Dual approval on sensitive financial transactions above threshold
- Access requests with audit trail for elevated permissions and overrides
- Security alerts for self-approval attempts, repeated denied requests, and admin override patterns
- Compliance task system tying due dates to specific regulations with caseworker assignment
- Backup logs and audit trails on every consequential action
Data residency & hosting
Our products are hosted in US data centers under SOC 2 Type II-certified infrastructure. We can provide hosting-provider attestation documents on request as part of customer due diligence.
What compliance is not
We are honest about what software can and can’t do. Our products give your organization the data structures, deadline tracking, audit logs, and access controls to operate compliantly. Compliance itself is a function of your policies, your training, your staff judgment, and your governance — we equip those things; we don’t replace them.