BlueMirror is being built to hold some of the most sensitive information a family has. That obligation shapes the engineering before the first member is ever served. The service launches in the first half of 2027; here is the posture it launches with.
The short version
- Healthcare-grade by design. Where the service touches health information, it is built to HIPAA’s standards: for institutional deployments as a contractual obligation, and for families as the same discipline applied voluntarily.
- Encrypted everywhere. Information is encrypted in transit and at rest, with modern, industry-standard cryptography and managed keys.
- Compartmented by architecture. Health, money, home, and family information live in separate contexts with separate permissions. A breach of one compartment is not a breach of a life. This is the same structure that powers the consent model on the privacy page, one design serving both.
- Least privilege, human and machine. People and system components alike get access to the minimum needed for the task at hand, and nothing stands between an action and its record.
- Everything auditable. Every action the service takes is logged (what it knew, what it did, on whose permission) and retained to healthcare recordkeeping standards. Auditability is a product feature, not just an internal control.
- Scam-aware by mission. Older adults are the most targeted fraud population in the country. The service is designed to notice and flag the patterns (the urgent caller, the strange charge, the too-good offer) and its own boundaries (visible actions, cancel windows, no secret instructions) are built so it cannot be turned into the scammer’s tool.
For health plans, PACE organizations, and providers
Institutional deployments come with the paperwork you require: business associate agreements, security documentation, audit support, and defined data-handling terms per engagement. Independent security assessment is planned ahead of institutional launch; current status and documentation are available in direct conversation. Start here.
Reporting a vulnerability
If you find a security issue on this site or, after launch, in the service, tell us via the contact page marked “security.” A person reads it, we respond, and we will thank you rather than threaten you.
Copy pending formal items pending: assessment/certification status, disclosure policy text, subprocessor list, added as they are completed