SecurityHow your account is protected
Whether you are a veteran deciding to make an account or a service officer deciding whether to hand VetPath to one, here is exactly how your information is handled. Every line on this page was checked against our code and our live database. Nothing here is a plan for later.
Last checked October 2, 2026.
The short version
- Row-level security is on for every one of VetPath's database tables - 7 of 7.
- We do not sell your data, and no advertising pixel is switched on.
- There is no AI in VetPath. Your plan comes from fixed rules we wrote.
- You can delete your whole account yourself, in one step, from your profile page.
- An automated check tests the site, sign-in, and database about every 30 minutes.
What we store
Without an account, nothing you type leaves your browser unless you send us a note through the feedback box. With an account, we store your email address, your name, and your email settings; your intake answers and gameplan; the notes you write; the dates you open VetPath while signed in (the date only, counted as totals); a record of which check-in emails we sent you; any feedback you send while signed in; the campaign tag on the link you first arrived from, or a partner office's random code if its link brought you; your separation month if you give it; and the date you first opened each free accredited-help link in your plan. Your password is handled by our sign-in provider and kept only as a scrambled hash that cannot be read back. The full list, including which questions are sensitive and optional, is on the
privacy page.
Locked to you by the database itself
Our database has 7 tables, and row-level security is switched on for all 7. That means the database, not just our website code, decides who can see each row:
- Your profile, plan, notes, visit dates, and email history can only be read while signed in as you.
- Feedback notes can be dropped in by anyone, but no one can read them back through the site - only the founders, inside the database dashboard.
- Two internal tables - our settings and the partner-code list - have no public access at all.
The one exception is a calendar link you choose to create: anyone holding that private link sees your plan's phase dates, with no name or email, and it stops working when you delete your account. Our automated check also asks the database for every user table without signing in, about every 30 minutes, and confirms it gets nothing back.
Never sold, never shared with advertisers
We do not sell, rent, or trade your information, and we do not share it with advertisers. No VA office or other government agency can see your account. If a county or state veterans service office hands out VetPath, it sees only the counts-only partner report. If any of that ever changes, the privacy page will say so first.
Counting visits without tracking you
We count page views with GoatCounter, an open-source counter with no cookies, no personal identifiers, and nothing that links a visit to your account. It also counts a few named button presses, such as building a plan, as plain totals. If your browser sends a Do Not Track or Global Privacy Control signal, we do not count the visit at all. No advertising pixel is switched on: the slots for them in our code are empty, and if that ever changes, the privacy page will say so first.
No AI
VetPath has no AI in it. Your plan, benefit matches, and career fits come from fixed rules we wrote, and every recommendation shows its reasons. No AI model reads your answers, and none is trained on them. The site is built on four code libraries - Next.js, React, React DOM, and Supabase's client - and none of them is an AI service.
Delete your account yourself
On your profile page,
Delete my account removes your login and everything saved to it - plan, answers, notes, visit dates, email history, and any feedback you sent while signed in - from our database right away. It also clears VetPath's saved data from the browser you use to do it. No email to us, no reason needed.
Four things it cannot reach: emails already delivered to your inbox; delivery records our email provider keeps for a limited time, and short-lived service logs at our hosting provider, which expire on their own schedule; the anonymous page counts (they were never tied to you); and a copy of your plan saved in another browser where you used VetPath. Sign out there, or clear that browser's site data, to remove it.
Where it lives
Your account and plan are stored by Supabase in Amazon Web Services' West US (Oregon) region. Supabase encrypts stored data with AES-256 and data in transit with TLS, and reports that it is SOC 2 Type 2 compliant - see
supabase.com/security. The website is served by GitHub Pages over HTTPS. Emails come from vetpathusa.com through Resend, with SPF, DKIM, and DMARC set to reject mail that only pretends to be us.
Watched around the clock
About every 30 minutes, an automated check on GitHub loads our home page, the benefits library, the separation checklist, and the trust page, confirms the sign-in service is answering, and runs the database check above. If anything fails, we get an alert. Every run is logged in public on
GitHub.
Found a security problem?
Email
kaleb@vetpathusa.com. A person reads every report. Tell us what you found and how to see it, and please do not open or change anyone else's data to prove it.
What we have not done yet: VetPath has not had an independent security audit, and accounts do not offer two-step sign-in. Our database provider is audited; we are not. When either changes, this page will say so.
Privacy & data Where our numbers come from