Skip to main content
Security

How Clinic OS protects clinic data

Security is part of the product architecture — tenancy, permissions, encryption, and auditability.

  • Clinic isolation
  • RBAC
  • TLS
  • Audit
Controls

Platform security controls

Clinic-scoped data

Queries and permissions are scoped to the active clinic context.

Least-privilege roles

Admin navigation and actions respect role permissions and plan entitlements.

Transport encryption

Public and admin traffic use HTTPS/TLS in production deployments.

Operational audit

Sensitive workflows leave audit evidence for clinic operators.

Human approval for AI

Consequential AI actions draft first — staff approve before patient or finance impact.

Secure billing options

Clinic billing workflows with optional third-party payment integrations (for example Stripe when connected); invoice trails for larger deployments.

Security questionnaire?

Email the product team for enterprise security review requests.

Contact product team