WylariWylari

Security at Wylari

Last updated: August 10, 2026

Daycare providers trust Wylari with information about children and families — we treat that as the most sensitive data a small business can hold. This page explains, in plain language, how it is protected.

Every daycare's data is isolated — in the database itself

Each provider's data is separated using PostgreSQL row-level security, enforced by the database engine on every query, not just by application code. Even a bug in the application cannot return one daycare's records to another: the database refuses. Inside the parent portal, access is further scoped to the signed-in family, the same way — a parent can only ever see their own children's information, enforced at the database layer.

Encryption & credentials

Access control

Health records & HIPAA — an honest answer

Providers store immunization records, allergy and medication notes, and scanned health forms in Wylari, so we get asked about HIPAA. Here is the straight answer: HIPAA does not apply to childcare records. HIPAA governs healthcare providers, insurers, and their vendors — "covered entities" in the law. A childcare program is not one. When a family hands their daycare an immunization record, that copy is legally a childcare record, the same as it would be in a paper file at the daycare. That's not a loophole we found; it's how the law is written, and it's why no daycare software can truthfully wear a "HIPAA compliant" badge for this data — be wary of any that does.

What matters is how the data is actually protected, so we treat health records as if the strictest rules did apply:

Where data lives

Wylari runs on servers in the United States (Phoenix, Arizona), with uploaded files mirrored to encrypted object storage, also in the United States. The small set of service providers we use — and exactly what each one processes — is listed in our Data Processing Addendum. We do not sell personal information, and analytics never run on the check-in kiosk or the parent portal.

Payments

Wylari never touches card numbers. Subscription payments are handled entirely by our payment processor; tuition tracking inside Wylari is record-keeping only — no money moves through us.

If something goes wrong

If we become aware of a breach affecting a provider's data, we commit to notifying that provider without undue delay with what we know, so they can meet their own obligations to families — the same commitment written into our DPA.

Certifications. Wylari does not currently hold a SOC 2 or ISO 27001 attestation — audits sized for enterprises, not (yet) for software built for home daycares. The practices above are simply how the product is built. If your organization has a security questionnaire, we're glad to complete it: security@wylari.com.

Reporting a vulnerability

Found something? Please tell us at security@wylari.com. We read every report, we'll respond promptly, and we won't take action against good-faith research that respects families' data.