Security

Built so one practice can never see another

Isolation is enforced in two independent layers, and both are tested on every build. A failure in either is a release blocker rather than a ticket.

How it works

Two layers of isolation

Every query is scoped in the data access layer, and the database enforces row-level security underneath it. A developer cannot write an unscoped query by accident.

Append-only audit

Every state-changing action is recorded with who, what and when. There is no update path and no delete path, enforced in four places including the database itself.

Second factor for administrators

Mandatory for anybody who can change what a role may do, and not something a clinic can turn off for one account.

Support access is time-boxed

Nobody at our end can read your records without starting a session that expires, and that appears in your own audit log with the reason attached.

No images, ever

Radiographs and report images are not stored by this system at all. We hold a link into your imaging system.

Your region

Records live in the region chosen when the practice is created, and are not moved afterwards.