Security
Clinith OS is designed to protect clinic and patient data through tenant isolation, least privilege, and auditability—built for real-world operations.
Tenant isolation
All staff and clinic operations are scoped by clinic. Sensitive access paths are guarded and audited.
Least privilege
Role-based access control, custom permissions, and server-side checks on actions and API routes.
Auditability
Key access and changes are logged. Clinics can export audit logs for review and compliance workflows.
Operational controls
- Session idle timeout enforcement
- Optional MFA (TOTP) for staff
- Retention policies for inactive patient data
- Webhook verification for external integrations
Compliance posture
The platform includes features aligned with DPDP and HIPAA-style controls (audit trails, access control, retention, patient export/erasure workflows).
For DPDP and HIPAA mapping, see our compliance page.
Contact security