Trust Center
See how Pairing protects your clients' information, who at your agency can see it, and which outside companies handle it for us.
Updated September 28, 2026
Business Associate Agreement
Signed before any data goes in
We sign a BAA with your agency before any of your client information goes into Pairing, as HIPAA requires.
Where your data lives
AWS, in the United States
Amazon Web Services has signed a Business Associate Addendum covering Pairing's account.
Who owns it
Your agency
We use it only to run Pairing for you. We never sell it or use it for advertising.
Real client data in testing
Never
We build and test Pairing with made-up children, staff and addresses, like the ones in the recordings on this site.
Safeguards
Each one below is in place now, in the app or in how we run it.
Who can see what
- Access follows each person's roleBIs see their own sessions, supervisors see their team, and directors see the whole agency.
- Agencies are walled off in the databaseThe database itself keeps each agency's records apart, so a mistake on a screen can't show one agency another's clients.
- Parents see only their own childParent access stays off until your agency turns it on for that child.
- Invite onlyNobody can sign up. Your agency invites each person, and deactivating someone ends their access.
Signing in
- Signed out after 15 minutes of inactivityPairing signs out a screen left open on a desk or in a car.
- Every sign-in ends within 12 hoursEven a busy session ends, so a forgotten device doesn't stay signed in.
- Five failed sign-ins lock the accountSign-in pauses for up to 15 minutes, which stops password guessing.
- A password reset signs you out everywhereEvery signed-in device loses access when the password changes.
A record of who did what
- Every change is recordedPairing records who created or changed a record, and when.
- Refused attempts are recorded tooWhen someone tries to open something their role doesn't allow, Pairing refuses and writes it down.
- Nobody can edit the recordAudit entries can't be changed or deleted from inside Pairing.
Infrastructure
- Hosted in the United StatesPairing runs on Amazon Web Services, under Amazon's Business Associate Addendum.
- Encrypted connectionsEverything moving between your screen and Pairing is encrypted on the way.
- Cloud activity is loggedEvery action in Pairing's AWS account is recorded, and we keep those records for a year.
Privacy by design
- Notifications carry no client detailsA notification says something needs you. The details appear after you sign in.
- Our admin tools don't show client recordsThe tools we use to support agencies leave client information out.
- Made-up data for building and testingNo real client information goes into development or testing.
How we work
- We attack our own safeguardsBefore an access rule ships, our engineering rules require us to try to get around it.
- You hear about an incident from usIf a security incident affects your data, we notify your agency without unreasonable delay, as HIPAA and our agreement require.
- Your data comes back if you leaveWe give you a copy on request, then delete ours or return it as you direct.
Subprocessors
The outside companies that store or carry agency data for Pairing.
| Company | What it does for Pairing | Location |
|---|---|---|
Amazon Web Servicesaws.amazon.com |
Runs Pairing's servers and database, handles sign-in, and sends account emails such as invitations and password resets. | United States |
Cloudflarecloudflare.com |
Carries traffic to and from Pairing's web addresses and shields them from attacks. | Worldwide, nearest data center |
This list covers the Pairing app. For this website, and for emails with people who contact us, see our Privacy Policy.
Your data
Pairing holds what a scheduler needs and leaves the clinical record where it is.
In Pairing
- About each childName, date of birth or age, address, parent or guardian contact details, approved weekly hours and treatment plan dates.
- Care needs, from a fixed listSuch as non-verbal or a seizure protocol, so Pairing suggests a BI who can meet them. There's no free-text field.
- About your staffName, email, phone, address, role, credential level, hours and availability.
- The work itselfSessions, time off, PST and supervision records, team messages and messages from parents.
Not in Pairing
- Session notes and clinical recordsThey stay in the system you use now.
- Diagnoses
- Insurance or Medicaid numbers
- Social Security numbers
- Payment card numbers
Found a security problem, or have a question?
Email [email protected]. Someone on the Pairing team reads every message and usually replies within one business day.