Security and trust
Security, clearly explained.
PetCremLog is built around a practical promise: the people working in your facility should know which records they can access, what the custody timeline says, and how to take their data with them.
Last reviewed: September 6, 2026
Account access and identity
Passwordless access means users sign in with an email code, with passkeys available where configured. Each operator has a separate identity and name in the facility account. Access is scoped to that account, so an operator cannot use a case URL to read another facility's records.
Custody records and retention
Custody events are append-only. A status advance records the operator, activity time, and recording time rather than rewriting an earlier event. Notes and corrections are additional entries: the original stays visible, together with the correction reason and author. Only an owner can correct the last eligible status advance. A case can be archived at any active stage, including intake, with an optional note. Archive and restoration entries preserve the actor, date, and any note or restoration reason. An owner or administrator can restore an archived case.
Delete moves a case to Trash for any staff member and preserves its custody history and existing archive metadata. Staff can restore it before the retention deadline. The trash record shows who moved it, when, and its automatic purge date six calendar months later. Only the owner can permanently delete a case from Trash; automatic deletion runs daily for cases whose deadline has arrived.
Status links
A public status link is a scoped, read-only view for a family or partner clinic. It shows only the cases assigned to that recipient and does not expose internal notes or custody photos. A link belongs to a recipient contact and can show more than one case. Anyone holding it can open it. Links do not expire automatically, and returned cases are not removed by age. Operators can manually disable or rotate a link; a disabled or replaced link no longer works. Archived, trashed, and training cases are excluded from the real recipient view.
Uploads and exports
Case photos are treated as part of the private operational record. Custody photos accept PNG, JPEG, or WebP images up to 10 MB and are not shown on public status links. Authenticated owners can download separate CSVs or prepare a private workspace ZIP containing structured operational records, available case documents, and stored operational files. Trashed cases are excluded from ordinary operational CSVs and kept in a separate trash section of the ZIP with their original files and a Case Record. The ZIP does not generate a new certificate or tracking label for a trashed case. Training data is clearly separated. PDFs in the ZIP are generated for that export; they are not a guaranteed archive of every previously issued document. Temporary ZIP downloads expire, and credentials and access tokens are never included.
Storage and recovery
The application database is automatically replicated to off-server storage. A separate hourly backup routine copies the database and uploaded files into encrypted off-server snapshots, with a 30-day retention policy. An automated daily check restores a snapshot in isolation and checks the database and referenced files. A workspace export lets you keep an independent copy of your operational records. Exporting data is not the same as restoring a workspace.
Restoration is not self-service. Contact support to discuss whether recovery is possible before relying on it. Do not assume that a permanently deleted case or workspace can be recovered.
Payments and what we do not claim
Creem is PetCremLog's Merchant of Record for new subscriptions. Checkout and payment handling occur through Creem, and PetCremLog does not store full card details.
PetCremLog is operational recordkeeping software, not legal or compliance software. PetCremLog does not claim HIPAA, SOC 2, GDPR, or another legal/compliance certification.
Questions
For security or privacy questions, contact [email protected].