Public marketing site
Product information, pricing, methodology, security disclosures, and business inquiries. No case files.
CurrentData safeguards
Reentry Address keeps product information and payment activity separate from the protected SafeAddress workspace used for address-screening records.
Current boundary
The public Reentry Address site explains the product and collects business inquiries. It should not receive client names, registry details, victim information, medical records, Social Security numbers, court files, or other case documents.
Product information, pricing, methodology, security disclosures, and business inquiries. No case files.
CurrentBuyer and payment details are handled through the configured payment provider. Screening inputs do not belong in checkout fields.
Separate serviceNamed invited accounts, hashed passwords, secure sessions, organization roles, server-side saved screenings, and audit events.
CurrentCurrent operating model
SafeAddress uses named access and server-side organization checks. The controls below distinguish what exists now from work that remains.
Users sign in with individual accounts. Passwords are stored as hashes, and application sessions use protected cookies rather than shared login links.
Organization and platform roles are checked server-side so access can be limited and accounts can be deactivated without deleting history.
Protected records are associated with an organization, and access checks occur before records are returned or changed.
Accounts, sessions, saved screenings, and workflow records are stored in the application database instead of relying on browser-only storage.
Security-relevant and workflow actions can be recorded with the user, organization, action, and time to support review and troubleshooting.
SafeAddress does not claim MFA, SOC 2, CJIS, HIPAA, independent penetration testing, or other controls until they are implemented and verified.
Data minimization
A housing-screening product should not become a second criminal-history database.
Use case identifiers or initials where full identity is unnecessary for the task.
Saved screenings are retained for 90 days, restricted-access audit events for 365 days, and resolved data reports for 180 days under the published retention schedule.
Supporting documents should use private object storage and short-lived download links.
Platform staff access should be time-limited, logged, approved, and restricted to what support requires.
Claims we will not make
Trust collapses when a product claims certifications or protections it has not earned.
A clearer first step
Organization access begins with a review of the workflow, data involved, and controls required for the intended use.