Security

Enterprise-GradeSecurity

We implement multiple layers of security to protect your data and ensure the integrity of our platform

Security Measures

End-to-End Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256

Two-Factor Authentication

Optional TOTP two-factor authentication for all users, required for administrators, with self-service recovery codes

Sign-In Alerts

Automatic email alerts when your account is accessed from a new device or country, with one-click device revocation

Re-Authentication for Sensitive Actions

Exporting data, deleting an account, or paid changes require re-entering your password, even while signed in

Access Controls

Role-based access controls and principle of least privilege, with trusted-device management

Infrastructure Security

Hosted on enterprise-grade cloud infrastructure with continuous monitoring and alerting

Compliance & Review

Pursuing SOC 2 Type II certification, with ongoing security review and dependency scanning

Data Protection

Encryption & Isolation

  • • AES-256 encryption for data at rest
  • • TLS 1.3 for data in transit
  • • Row-Level Security (RLS) for per-user data isolation
  • • Encrypted, signed session tokens (JWT)

Access Management

  • • Role-based access control (RBAC)
  • • Two-factor authentication (required for admins)
  • • Trusted-device management with one-click revocation
  • • Audit logging for organization actions

Infrastructure Security

Network Security

  • • Virtual Private Cloud (VPC)
  • • Web Application Firewall (WAF)
  • • DDoS protection
  • • Network segmentation

Application Security

  • • OWASP-aligned application hardening
  • • Dependency scanning
  • • Content Security Policy (CSP)
  • • Container security

Monitoring

  • • Continuous monitoring and alerting
  • • Error tracking and diagnostics
  • • Log aggregation and analysis
  • • Sign-in anomaly alerts

Security Contact

If you discover a security vulnerability or have security concerns, please contact us immediately:

Security Team: security@clinicalister.com

Response Time: Within 24 hours

Please do not publicly disclose security vulnerabilities. We follow responsible disclosure practices.