At the end of each period your supervisor reviews the hours and signs.
What comes out is — fixed with a
digest chained to the one before it, so any later change to any part of
the history is detectable.
Nobody can edit it afterwards. Not you, not your supervisor, not an
administrator, and not us; there is no code path that does. A mistake is
corrected by an amendment that sits beside the original and preserves
it, so the record shows both the error and the correction.
Two things, not one. The application exposes no operation that edits
or deletes a sealed record, for any role; and the database itself
refuses the change, so a bug or a script cannot do what the interface
will not. Each sealed period also carries a digest computed over its
contents and chained to the period before it.
Anyone with direct access to a database can alter bytes in it; no
software can promise otherwise, and we will not claim to. What the
chain gives you is that such a change cannot be quiet — the
digests stop agreeing, the break is reported, and it points at which
period changed. We test exactly that, by doing it: our build fails if
a record altered behind the software’s back is not detected.
That is a deliberately inconvenient design, and it is the only one worth
having. A record that could be quietly tidied is a record a board has no
reason to believe.
What stays yours
Everything you have finalized. If a subscription lapses, discovery and
the workspace pause — reading, exporting and verifying what you already
earned never do. You do not rent your own history.
What we will never hold
Any information that identifies a client. TripleRoute is not an
electronic health record and has no field that could hold one — no name,
no date of birth, no note, no treatment plan. Case discussion on this
platform stays de-identified, and the product is built so that this is
not a policy you have to trust us to follow.