Last updated: August 24, 2026
Tenerwise is designed to process sensitive childcare operational information, including information about children, families, and staff. This statement describes Tenerwise's security approach at a high level. It is not a certification, service-level agreement, guarantee against a security incident, or representation of compliance with a framework Tenerwise has not formally obtained.
Capitalized terms not defined in this Statement have the meanings given to them in the applicable Tenerwise Terms of Service, Authorized User Terms, or Data Processing Addendum.
Tenerwise applies a risk-based security approach centered on tenant-aware authorization, least-privilege access, secure development practices, and vendor oversight.
Tenerwise is designed to logically segregate each Center's data by tenant. Authorized Users access data according to role-based permissions and other applicable access scopes. For example, Center administrators may have broader access than staff users, while Family Users are limited to information associated with children they are authorized to access.
Data transmitted between users and Tenerwise over the public internet is protected using HTTPS/TLS. Tenerwise's hosted database and storage infrastructure is provided by Supabase, which states that storage disks and scheduled backups are encrypted at rest using AES-256.
Infrastructure encryption helps protect data against risks such as unauthorized access to underlying storage media or interception of network traffic. Encryption at rest and in transit does not replace application-level authorization: access by authenticated application processes is controlled through the tenant isolation and role-based access controls described above.
Tenerwise is built on established infrastructure providers, including Supabase (database and authentication) and Vercel (application hosting). Supabase is SOC 2 Type 2 compliant and has obtained ISO/IEC 27001 certification covering its defined platform and information security management system; these statuses apply to Supabase and do not represent an independent certification or attestation held by Tenerwise. Tenerwise evaluates the vendors that may process Center Data and requires appropriate contractual confidentiality, security, and data-use restrictions. Material subprocessors are identified in the Tenerwise Subprocessor List.
Tenerwise applies security considerations during development and testing, particularly for authentication, authorization, tenant isolation, and data-access functionality.
Access controls for sensitive application data are enforced at the database level through row-level security policies where appropriate, rather than relying solely on client-side interfaces to determine what a user may access.
Tenerwise reviews software dependencies and security-relevant updates based on risk and applies updates as appropriate.
Tenerwise maintains internal procedures designed to identify, contain, investigate, and remediate security incidents. Where a security incident affects Center Data, Tenerwise will provide notice to affected Centers as required by the Data Processing Addendum and applicable law.
Tenerwise may process health-related childcare information, such as allergy, immunization, medication, health, and incident records, in connection with a Center's operations. The presence of health-related information does not by itself mean that HIPAA applies to a particular Center or use of the Services.
Unless Tenerwise expressly enters into an applicable Business Associate Agreement and the Services are configured for the applicable HIPAA use case, Tenerwise does not offer the Services as a HIPAA business associate service. See the Terms of Service for additional information.
Tenerwise has not obtained its own SOC 2 examination or ISO 27001 certification and does not represent that it has obtained any external security certification unless and until such status has actually been achieved and can be substantiated.
HIPAA is a legal and regulatory framework rather than a general certification issued by the U.S. Department of Health and Human Services. Tenerwise does not represent the Services as a HIPAA business associate service except where Tenerwise expressly enters into an applicable Business Associate Agreement and the relevant service configuration and supporting infrastructure are established for that purpose.
Certifications or compliance reports held by infrastructure providers apply to those providers and their defined certification boundaries and do not automatically confer the same certification or compliance status on Tenerwise.
If you believe you've discovered a security vulnerability affecting Tenerwise, please contact us at support@tenerwise.com. We ask that you report it responsibly and avoid accessing or modifying data beyond what's necessary to demonstrate the issue.
Questions about this statement: support@tenerwise.com
Tenerwise LLC — 5900 Balcones Drive, Suite 100, Austin, TX 78731, United States — https://tenerwise.com