Security
Last updated 2026-08-07
StaffCurrent does not store your documents.
StaffCurrent stores names, credential types, and expiration dates. Your certificates, personnel files, health records, and client information stay with you.
That limit is intentional. Keeping documents out of StaffCurrent reduces the amount of sensitive information the service holds. The privacy policy describes what we store.
Encryption at rest
The database is stored on encrypted block storage provided by our hosting provider.
Backups run nightly and are encrypted before they are stored. The key needed to decrypt them is kept off the server, so the server cannot read its own stored backups. We have also tested restoring a backup and verified the restored data against production.
Encryption in transit
StaffCurrent uses HTTPS for all connections, with strict transport security enabled to help prevent unencrypted access.
StaffCurrent restricts which scripts can run, blocks third-party scripts and embedded content, and prevents other sites from displaying StaffCurrent pages inside their own. Additional browser security headers are enabled to reduce common web-based attacks.
Payments
Payments are handled by Stripe. Card details are entered directly with Stripe and never pass through StaffCurrent.
What is watched
StaffCurrent monitors site uptime, application errors, nightly backups, and the reminder emails. If any of those stop working, I’m alerted so the problem can be investigated.
Monitoring runs outside the StaffCurrent server, so alerts can still be sent if the server itself goes down.
Who has access
StaffCurrent is built and operated by Brian Kennedy as a sole proprietor. I’m the only person with administrative access to the service and its data.
Reporting a problem
Report security issues to support@staffcurrent.com. Include what you found and, if possible, the steps needed to reproduce it. I’ll review and respond to your report directly.
There is no bug bounty program. Please do not run automated scans, load tests, or other testing that could disrupt the service without permission. Contact support@staffcurrent.com first if you need to test something.