Less data is the design
The strongest security control in this product is what it never holds. Your tracker lives in your own browser’s local storage — facilities, staff credential rows, deadlines, attestations — and is not uploaded to us. There are no fields for patient or client information anywhere in the product, by design. Card numbers go to Stripe’s hosted checkout and never touch our systems. What we hold server-side is deliberately small: opt-in email addresses, callback requests with their consent records, and assistant transcripts.
How the service is built
Everything is served over HTTPS (TLS) on Cloudflare’s edge network. The backend surface is minimal — a small set of serverless functions with narrowly scoped storage, no traditional servers to patch, no database of accounts, and no passwords to breach because there are no password accounts. We run no third-party advertising or cross-site tracking scripts. Access to the stored data is limited to Teryli Systems LLC.
Payments
Payments are processed by Stripe, a PCI-DSS Level 1 certified processor, on Stripe’s own pages. We never receive, transmit, or store card numbers.
Reporting a vulnerability
If you believe you have found a security issue, email [email protected] with enough detail to reproduce it. We will acknowledge within five business days, work with you in good faith, and credit you if you want credit. We will not pursue good-faith security research conducted without harming users or data; please do not access data that is not yours, and give us reasonable time to fix before public disclosure.
Renewal Radar is an independent product of Teryli Systems LLC and is not affiliated with, endorsed by, or acting for the California Department of Health Care Services or any government agency. Dates and amounts are computed from public sources for your convenience, are informational only, and are not legal or compliance advice. Reminders are a convenience, not a guarantee of delivery. You remain solely responsible for meeting every regulatory deadline.