ASL DIRECT Secure bilingual intake

Security and readiness

Designed for a controlled, auditable launch

Security is treated as a set of technical controls and operating responsibilities—not as a one-time claim.

Application isolation

The API, voice gateway, worker, database, service account, configuration, and backup paths are isolated from other Droplet applications. PostgreSQL and Node.js application ports bind only to loopback.

Identity and tenant boundaries

Runtime database access uses a restricted role, tenant-scoped row security, separate migration credentials, API-key controls, and auditable administrative operations.

Transport and delivery

The public site uses HTTPS. Twilio requests are signature-verified, and completed intakes are designed for signed, idempotent delivery with retries, reconciliation, and dead-letter handling.

Backups and launch gates

Daily local database backups are active and restore-readable. Encrypted off-Droplet backup, production provider credentials, supervised calls, alert ownership, delivery acceptance, and a full restore exercise remain required before real client information.

Report responsibly

Do not place secrets, caller information, or vulnerability details in public issues. Security reporting instructions are maintained in the repository’s SECURITY.md file.

Find support for a legal matterStrengthen your firm’s intakeReturn to the two choices
Help / Ayuda