Security
Security, in plain language.
Teryli handles coordination work for behavioral health teams, so security isn’t a feature we added — it’s a constraint we designed inside from day one. Here’s what that means, concretely.
How the workspace protects data
- Encryption. Data is encrypted in transit and at rest.
- Access control. Every user signs in with authenticated credentials, and what they can see is governed by their role and organization.
- Automatic session locks. Sessions lock after 15 minutes of inactivity — a workstation left open at a nurses’ station doesn’t stay open.
- Tenant isolation. Each organization’s data lives in its own tenant space; one organization cannot read another’s records.
Scope, honestly stated
- Teryli is an operational coordination layer — not an EHR, not a clinical-records system. It is intentionally small in scope, which keeps its security surface small too.
- Our public demo runs entirely on synthetic, non-real data. No client information is used to show the product.
- This marketing site (teryli.com) collects no client data and is not a place to send PHI. See our Privacy Policy.
Neutral by design
Teryli is a neutral coordination layer. We don’t sell placement, and facilities can’t pay to rank higher, appear first, or be recommended. Search results are driven by clinical fit and the criteria your team enters — never by who pays us.
We charge the teams doing the placing for the software they use. We’re never paid for a referral, a placement, or an admission, and no facility can buy its way into your results or to the top of them. That neutrality isn’t a feature we added — it’s the reason the directory is worth trusting.
What “verified” means
On Teryli, verified means we checked it — never that a program paid. Teryli confirms a program’s licensure, accreditation, and level of care as of the date shown. Verification reflects the information available at that time; it isn’t an endorsement or a clinical recommendation, and it’s never something a program can buy. Always confirm current availability and fit directly with the program.
Payments
Checkout and billing for Directory Access run on Stripe’s hosted, PCI-certified payment pages. Card numbers go directly to Stripe and never touch teryli.com or our servers — we keep only the subscription record: who subscribed, and whether it’s active.
Working with your organization
Security expectations in behavioral health are specific — BAAs, access reviews, data-handling questions. We’d rather walk through yours directly than gesture at badges. Bring your security questions to a workflow review, or raise them any time at chris@teryli.com.
Reporting a concern
If you believe you’ve found a security issue involving Teryli, email chris@teryli.com with the details. We take reports seriously and will respond promptly. The same contact is published at /.well-known/security.txt.