We implement multiple layers of security to protect your data and ensure the integrity of our platform
All data is encrypted in transit using TLS 1.3 and at rest using AES-256
Optional TOTP two-factor authentication for all users, required for administrators, with self-service recovery codes
Automatic email alerts when your account is accessed from a new device or country, with one-click device revocation
Exporting data, deleting an account, or paid changes require re-entering your password, even while signed in
Role-based access controls and principle of least privilege, with trusted-device management
Hosted on enterprise-grade cloud infrastructure with continuous monitoring and alerting
Pursuing SOC 2 Type II certification, with ongoing security review and dependency scanning
If you discover a security vulnerability or have security concerns, please contact us immediately:
Security Team: security@clinicalister.com
Response Time: Within 24 hours
Please do not publicly disclose security vulnerabilities. We follow responsible disclosure practices.