Security

Clinith OS is designed to protect clinic and patient data through tenant isolation, least privilege, and auditability—built for real-world operations.

Tenant isolation
All staff and clinic operations are scoped by clinic. Sensitive access paths are guarded and audited.
Least privilege
Role-based access control, custom permissions, and server-side checks on actions and API routes.
Auditability
Key access and changes are logged. Clinics can export audit logs for review and compliance workflows.
Operational controls
  • Session idle timeout enforcement
  • Optional MFA (TOTP) for staff
  • Retention policies for inactive patient data
  • Webhook verification for external integrations
Compliance posture

The platform includes features aligned with DPDP and HIPAA-style controls (audit trails, access control, retention, patient export/erasure workflows).

For DPDP and HIPAA mapping, see our compliance page.

Contact security

Security review?

We can share architecture notes and subprocessors on request.