Identity and access
Consumer, staff, business owner, partner, and administrator roles are planned around strong authentication, scoped permissions, session controls, and account recovery protections.
FillR is being designed around identity, privacy, auditability, secure communication, and careful integration with payment, insurance, and scheduling systems.
The public website is served over HTTPS with automatic certificate renewal.
Inquiry submissions are validated, rate-limited, and stored server-side for follow-up.
Product-account features are being planned around role-based access, audit logs, and least-privilege data handling.
FillR's public website has a simple security model. The full platform will require stronger controls because appointment, payment, communication, insurance, and business operations data can be sensitive.
Consumer, staff, business owner, partner, and administrator roles are planned around strong authentication, scoped permissions, session controls, and account recovery protections.
Sensitive records are intended to be encrypted in transit and at rest, retained only as needed, and separated by customer, business, region, and permission boundary.
Security-relevant actions are expected to produce logs for access, booking changes, staff actions, messages, insurance events, payment events, exports, and administrator activity.
Scheduling, payment, insurance clearinghouse, calendar, messaging, and analytics integrations are planned with scoped credentials, secure storage, and monitoring for failures or abuse.
FillR is being designed to limit default exposure of personal contact details, keep conversations appointment-linked, and disclose when estimates or plan data are incomplete.
Production operations are expected to include alerting, backup and recovery procedures, vulnerability triage, access reviews, dependency updates, and customer communication workflows.
Use the contact page for responsible disclosure, suspected abuse, or questions about data handling. Do not include passwords, payment card numbers, insurance credentials, or sensitive health information in the message.