Trust Centre

Security Centre.

A plain-language summary of the security posture behind Clinical Confidence.

Platform security

Clinical Confidence runs on managed, hardened infrastructure. Access to production systems is restricted, logged and reviewed.

Authentication

Sign-in is handled by a dedicated authentication service with industry-standard password hashing, email verification and secure session tokens. Password reset flows use single-use, time-limited links.

Encryption

All data is encrypted in transit using TLS. Data at rest is encrypted at the storage layer. File previews use short-lived private links so URLs cannot be re-used indefinitely.

Secure storage

Documents live in a private storage area with owner-scoped access rules. Per-record owner access controls in the database ensure that records are only visible to the professional who created them.

Backups

The platform relies on managed database backups with regular snapshots and point-in-time recovery windows. Restore procedures are exercised during platform maintenance.

Responsible disclosure

If you believe you have discovered a security issue in Clinical Confidence, please contact us before disclosing it publicly. We will acknowledge your report, investigate promptly and credit you when a fix ships (with your permission).

Future security roadmap

Planned improvements include optional multi-factor authentication, user-facing audit logs and organisation-level access controls for teams. New security capabilities will be described here as they ship.