Client Resource Project

Security and Compliance

Our approach to protecting the website, limiting the information we collect, responding to security concerns, and communicating honestly about compliance.

Effective and last updated: August 9, 2026

We limit collection. The site should not receive client files, therapy notes, medical records, or other highly sensitive case information.
We use layered safeguards. Security includes technical protections, restricted access, maintenance, monitoring, and careful handling practices.
Users share responsibility. Strong unique passwords, secure devices, and prompt reporting help protect accounts.
No unsupported certifications. We do not claim HIPAA, SOC 2, ISO 27001, or PCI DSS compliance unless expressly stated after verification.

1. Our security approach

Client Resource Project provides public educational articles, worksheets, guides, activities, resource information, newsletters, and related tools. We take reasonable steps to protect the information and systems used to provide these services. Our approach is based on collecting only what is reasonably needed, limiting access, maintaining software, preparing for incidents, and reviewing safeguards as the site changes.

This page is a public explanation of our approach. It is not a warranty, audit report, certification, service-level agreement, or disclosure of security details that could make the site easier to attack. Our Privacy Policy explains what information we collect and how it is used; our Terms and Conditions govern use of the site.

2. Scope of this statement

This statement applies to clientresourceproject.org and the website features that link to it. It addresses public pages, article search, downloads, account features if offered, newsletter subscriptions, administrative systems, and information submitted directly through the site.

Third-party websites, resources, embedded content, email providers, hosting platforms, and other services have their own security practices. We evaluate service providers as reasonably appropriate, but we do not control every aspect of their systems. Following an external link takes you outside the scope of this statement.

3. Administrative and technical safeguards

Safeguards may vary by feature and risk. Measures used or expected for the site include:

  • encrypted HTTPS connections for supported web traffic;
  • restricted administrative access and separate administrative authentication;
  • password hashing rather than storage of readable account passwords;
  • server-side validation, prepared database queries, and protections against unauthorized requests;
  • least-privilege access appropriate to a person’s responsibilities;
  • security updates for the website, server software, dependencies, and administrative devices;
  • logging, monitoring, backups, and recovery measures appropriate to the site’s size and risk; and
  • review and removal of information that the site does not need to retain.

We may change individual safeguards as technology and risks evolve. For security reasons, we do not publish network diagrams, software versions, credentials, recovery keys, vulnerability details, or internal response procedures.

4. Account and credential security

If user accounts are offered, passwords are intended to be processed using secure password-hashing functions. Administrative and privileged access should be more restricted than ordinary public access. Where supported and appropriate, additional controls may include multifactor authentication, rate limiting, temporary lockouts, session expiration, anti-automation measures, and notifications about important account activity.

We will never ask you to send your password by email. You are responsible for using a strong, unique password, protecting your email account and devices, signing out of shared devices, and notifying us promptly if you suspect unauthorized access. We may reset credentials, end sessions, restrict access, or temporarily disable an account when reasonably necessary to protect the site or its users.

5. Data minimization and retention

A central security practice is not collecting information the site does not need. Newsletter forms should request only the information reasonably needed to manage the subscription. Account, contact, correction, or resource-submission features should be limited to the information needed to provide and protect that feature.

Do not submit confidential client or patient information. Do not enter therapy notes, case records, diagnoses connected to an identifiable person, protected health information, Social Security numbers, financial-account credentials, legal case files, abuse reports, school records, or other confidential service-recipient information anywhere on the site.

Information is retained only as reasonably needed for the purposes described in the Privacy Policy, operational continuity, fraud prevention, dispute resolution, legal obligations, and security. Backup copies and logs may persist for a limited period after active information is deleted.

6. Hosting and service providers

We may rely on providers for hosting, databases, email delivery, backups, security, analytics, domain services, or other operations. Access should be limited to what a provider needs to perform its service. We consider the sensitivity of information, access controls, contractual protections, security practices, location, and the ability to delete or return information when selecting or reviewing providers.

No vendor relationship eliminates risk. If a new provider materially changes how personal information is handled, we will update the Privacy Policy or other notice as appropriate.

7. Maintenance, logging, and monitoring

We may maintain operational and security logs to identify errors, suspicious requests, abuse, unauthorized access attempts, malware, or service interruptions. Logs may include information such as date and time, IP address, device or browser details, requested pages, authentication events, and technical error information, as described in the Privacy Policy.

We review and update the site as reasonably appropriate, including security patches, dependency updates, access reviews, configuration changes, and removal of unused features or accounts. Monitoring does not mean every event is reviewed in real time or that every attack can be detected before harm occurs.

8. Backups, recovery, and availability

Reasonable backup and recovery practices may be used to restore important website content and operational data following accidental loss, technical failure, corruption, or a security event. Backups may be encrypted or access-restricted where supported and appropriate, retained on a schedule, and periodically replaced.

Backups reduce—but do not eliminate—the risk of permanent loss. We do not guarantee uninterrupted availability, that every item can be restored, or that a recovery will occur within a particular period. Users should retain their own lawful copies of resources they need for continuing work.

9. Security incidents and notification

If we become aware of a suspected security incident, we may investigate, preserve relevant information, restrict access, reset credentials, isolate affected services, restore systems, contact providers or authorities, and take other reasonable containment and recovery measures.

If an incident involving personal information triggers a legal notification duty, we will provide notice to affected individuals and regulators as required by applicable law. The timing, content, and method of notice will depend on the facts, the type of information involved, applicable law, law-enforcement needs, and the information available during the investigation.

10. Responsible vulnerability reporting

If you believe you found a security vulnerability, email security@clientresourceproject.org. Include the affected URL or feature, a clear description, steps needed to reproduce the issue, the date observed, and a safe way to contact you. Do not include passwords, private data, client information, or more evidence than is necessary to explain the issue.

Please do not exploit a vulnerability, access or alter another person’s data, attempt to bypass authentication, perform denial-of-service or high-volume testing, upload malware, use social engineering, disrupt the site, or publicly disclose an uncorrected issue. Stop testing and notify us immediately if you encounter nonpublic information. This reporting process does not authorize activity that would otherwise violate law or our Terms.

11. What users can do

  • Use a long, unique password for the site and for the email account connected to it.
  • Enable multifactor authentication on your email account and anywhere else it is offered.
  • Keep browsers, operating systems, security software, and devices updated.
  • Use trusted devices and networks; avoid entering credentials on shared or public devices.
  • Check the domain before signing in and be cautious with unexpected links or attachments.
  • Do not share confidential client, patient, student, or family information through the site.
  • Report suspicious messages, unauthorized account activity, or security concerns promptly.

12. HIPAA and protected health information

Client Resource Project is not presented as a HIPAA-compliant clinical platform. The site is not an electronic health record, patient portal, telehealth system, secure clinical messaging service, or case-management database. Do not use it to create, receive, maintain, or transmit protected health information on behalf of a HIPAA-regulated organization.

Publishing educational articles about HIPAA does not make the website a HIPAA covered entity or business associate. HIPAA applies based on an organization’s status and activities. A service that handles protected health information for a covered entity may require a business associate agreement and specific administrative, technical, physical, and contractual safeguards. Client Resource Project does not offer such an agreement through ordinary use of this website.

If you are a healthcare provider, social-service organization, school, insurer, business associate, or other regulated organization, you are responsible for determining whether your proposed use is permitted by HIPAA, Michigan law, professional confidentiality rules, agency policy, contractual requirements, and any other law that applies to you.

13. Other compliance frameworks

Unless a current written statement expressly says otherwise, Client Resource Project does not claim certification, attestation, or audited compliance with SOC 2, ISO/IEC 27001, PCI DSS, FedRAMP, HITRUST, or another voluntary security framework. Use of good practices associated with a framework is not the same as completing an audit or earning certification.

The site is not intended to accept payment-card information directly. If payment features are introduced, payment processing and the applicable compliance responsibilities must be evaluated before launch. Likewise, new features involving children’s personal information, user uploads, clinical data, employee records, or other sensitive information require a separate privacy, legal, and security review.

14. Security limitations

No website, transmission method, storage system, vendor, backup, or security control can guarantee absolute security. Mistakes, software flaws, device compromise, phishing, service-provider failures, natural events, and sophisticated attacks can occur even when reasonable safeguards are used.

This page does not promise that the Services will always be secure, available, uninterrupted, or free from harmful components. Security information is provided for transparency and may be revised as practices, vendors, features, threats, and legal obligations change. The disclaimers and liability limitations in our Terms also apply.

15. Changes to this statement

We may update this statement to reflect changes in technology, safeguards, vendors, legal requirements, or website features. The effective date at the top identifies the current version. Material changes may also be announced through the website or another appropriate channel.

16. Contact us

Client Resource Project — Security Contact

Email: security@clientresourceproject.org

Location: Grand Rapids, Michigan, United States

Use “Security Concern” in the subject line. Do not send passwords, protected health information, client records, or emergency requests to this address.