Platform security
Clinical Confidence runs on managed, hardened infrastructure. Access to production systems is restricted, logged and reviewed.
Authentication
Sign-in is handled by a dedicated authentication service with industry-standard password hashing, email verification and secure session tokens. Password reset flows use single-use, time-limited links.
Encryption
All data is encrypted in transit using TLS. Data at rest is encrypted at the storage layer. File previews use short-lived private links so URLs cannot be re-used indefinitely.
Secure storage
Documents live in a private storage area with owner-scoped access rules. Per-record owner access controls in the database ensure that records are only visible to the professional who created them.
Backups
The platform relies on managed database backups with regular snapshots and point-in-time recovery windows. Restore procedures are exercised during platform maintenance.
Responsible disclosure
If you believe you have discovered a security issue in Clinical Confidence, please contact us before disclosing it publicly. We will acknowledge your report, investigate promptly and credit you when a fix ships (with your permission).
Future security roadmap
Planned improvements include optional multi-factor authentication, user-facing audit logs and organisation-level access controls for teams. New security capabilities will be described here as they ship.
