Why Trust

Three choices most credential apps don't give you.

There are a handful of apps that say they hold healthcare credentials. Most are built to sell to your employer. A few sit on top of a single issuer's catalog. None — except Trust — combine three structural choices that change what the wallet actually does for you.

01

Worker-owned, not employer-owned.

Symplr, MedTrainer, HealthStream, and CredentialMyDoc are sold to hospitals and ambulatory groups. The clinician is a row in a roster — and when they switch jobs, the credentials don't follow. Trust is sold to the clinician. The wallet follows the worker.

02

Vendor-neutral, across every issuer.

Red Cross has a digital wallet for Red Cross cards. AHA has e-Verify for AHA cards. NREMT has the National Registry app for NREMT credentials. Each is excellent at its own issuer's footprint, and useless for everything else. Trust holds every credential, regardless of who issued it.

03

Privacy by architecture, not by promise.

Most apps store credentials on their servers because that's how apps usually work. Trust doesn't have servers — the wallet lives on your phone, protected by Face ID. There is no Trust account database to breach, no employer dashboard, no analytics on what's inside. The simplest privacy posture is the one where the data was never collected in the first place.

What "no server-side PHI database" actually means

Trust does not operate a database of clinician credentials. There is no server somewhere that holds a copy of your license number, your certification dates, or a scan of your card. When you add a credential in the app, it is written to your iPhone's encrypted local storage and nowhere else. There is no sync step to a Trust server, because there is no Trust server designed to receive that data in the first place.

That is a specific, checkable claim, not a policy promise. A policy promise says "we will not misuse your data." An architectural fact says "the data does not exist anywhere we could misuse it." Trust is built on the second kind of claim.

What Trust can see, and what it cannot

Trust can see anonymous, aggregate product-analytics signals: which screens get opened across all users, whether the app crashed, and coarse usage counts that carry no identifying information. Trust cannot see which credentials a specific person holds, when a specific license expires, what a specific scanned card image contains, or who is using the app on any given device. There is no admin panel where a Trust employee could look up an individual clinician's record, because no such record exists outside that clinician's phone.

This is the opposite of how most SaaS credentialing tools work. A cloud-hosted tracker — the kind sold to hospitals and staffing agencies — stores every worker's license data centrally, because the employer is the customer and the employer wants visibility into every worker's compliance status. That's a reasonable design for an employer-facing compliance tool. It is a bad design for a personal record that should belong to the person who earned it.

What happens on the device

Everything that makes Trust useful happens locally. Credential storage is local. Face ID authentication is handled by the iPhone's Secure Enclave, not by a Trust server checking a password. Renewal-reminder scheduling is computed on the device from the expiration dates you've entered — there is no server calculating your reminders and pushing them down. If your phone is offline, your wallet still opens, your credentials are still there, and your reminders still fire on schedule.

What leaves the phone

Nothing leaves the phone except anonymous product analytics: crash reports and coarse, non-identifying usage signals used to find bugs and understand which features get used. No credential data, no license numbers, no card images, and no personally identifying information leave the device. Renewal links open the regulator's own portal directly in your browser — Trust does not proxy that transaction or see what happens on the other side of it.

What this means if Trust disappeared tomorrow

Your credentials would still be on your phone. They were never anywhere else. You could still open the app, still see your license numbers and expiration dates, still export a PDF of your records. A company shutting down does not, by itself, delete data that company never held. That is the practical payoff of on-device architecture: your professional record does not depend on Trust's continued existence.

We made these three choices deliberately. They make Trust harder to build — and impossible to compromise.

Get the Trust App