Skip to main content
VCPMS Schedule a demo

Security

Built for state procurement

Below is a concise summary of VCPMS security, compliance, and data handling. Every claim here has a supporting answer in HEART4Victims' RFP response materials.

Multi-tenant data isolation

Every entity in VCPMS carries a tenant identifier with automatic filter enforcement at the query level. Unique constraints include the tenant partition. One state program's data is physically isolated from another - a query for Oklahoma data cannot return Maine records, by design.

Authentication

Authorization

Two orthogonal axes: user category (VboUser, VcaUser, SpaUser, AdvUser, LeaUser) enforced at the application-service level; hierarchical permissions (Pages.VcClaims, Pages.VcClaims.Edit, etc.) enforced per-action.

Audit logging

Compliance posture

Want to talk about VCPMS security?

We'll walk you through how VCPMS fits your program.

Schedule a demo