Security & Compliance

Healthcare-grade security,
independently verified

Clinit is certified against HIPAA, PCI DSS, SOC 2 Type II, and GDPR — the four most critical compliance frameworks for healthcare software. Your patients' data is protected at every layer.

HIPAA
PCI DSS
SOC 2
GDPR
4
Certifications
AES-256
Encryption
99.9%
Uptime SLA
72h
Breach Notice
Certifications

What each certification means for you

Every certification is independently verified — not self-declared. We provide documentation upon request.

HIPAA Compliant
HIPAA
HIPAA Compliant
Health Insurance Portability and Accountability Act

All Protected Health Information (PHI) is handled in strict accordance with HIPAA Privacy and Security Rules. We sign Business Associate Agreements (BAAs) with all clients and maintain full audit trails of every PHI access.

  • Business Associate Agreements (BAA) available for all plans
  • PHI encrypted at rest (AES-256) and in transit (TLS 1.3)
  • Role-based access controls — minimum necessary access
  • Audit log of every record access, edit, and deletion
  • Automatic session timeout after inactivity
  • Workforce security training program
PCI DSS
PCI DSS
PCI DSS Compliant
Payment Card Industry Data Security Standard

Payment card data is processed in full compliance with PCI DSS Level 1 — the highest tier. Raw card numbers are never stored on Clinit servers. All payment processing is handled by tokenised, certified payment gateways.

  • PCI DSS Level 1 via Paymob certified gateway
  • No raw card data stored on Clinit servers
  • Tokenised transactions with vault storage
  • Quarterly vulnerability scans by approved scanning vendor
  • Annual penetration testing
  • Encrypted payment links sent via HTTPS
SOC 2 Type II
SOC 2 Type II
SOC 2 Type II Audited
Service Organization Control 2 — Independent Audit

Our security controls are independently audited annually by a licensed CPA firm under the AICPA Trust Services Criteria. SOC 2 Type II means our controls are proven effective over an extended observation period — not just documented.

  • Annual independent audit by AICPA-accredited firm
  • Security, Availability, and Confidentiality Trust Service Criteria
  • Continuous control monitoring — not point-in-time
  • Incident response procedures tested and validated
  • Vendor risk management programme
  • Reports available under NDA upon request
GDPR Compliant
GDPR
GDPR Compliant
EU General Data Protection Regulation

Clinit supports full GDPR compliance for clinics serving EU patients. We act as a Data Processor under the regulation, and provide the contractual and technical mechanisms you need to meet your obligations as the Data Controller.

  • Data Processing Agreements (DPA) available for all clients
  • Right to access, portability, and erasure supported
  • Data breach notification within 72 hours
  • EU patient data stored on EU-region infrastructure
  • Explicit consent capture and audit trail
  • Privacy by design — data minimisation principles
Infrastructure

Security at every layer of the stack

From database to device, each layer of Clinit is independently secured and continuously monitored.

🔐
Encryption at Rest

All data stored on AES-256 encrypted volumes. Database, file storage, and backups are encrypted separately with rotating keys.

🔒
Encryption in Transit

All connections enforced over TLS 1.3 with HSTS. Weak cipher suites are rejected. Certificate pinning on mobile apps.

💾
Daily Backups

Automated encrypted backups every 24 hours with 30-day point-in-time recovery. Backup integrity is tested monthly.

🌐
99.9% Uptime SLA

Multi-region PostgreSQL on Supabase with automatic failover. Load-balanced API infrastructure on Vercel edge network.

🛡️
Penetration Testing

Annual third-party penetration tests on web, API, and mobile surfaces. Critical findings addressed within 48 hours.

👤
Access Controls

39-module RBAC permissions system. Every action is gated by role. Super-admin access requires MFA and is independently audited.

📋
Audit Logs

Tamper-proof, append-only audit log covering every record read, write, and delete. Exportable for compliance reviews.

🔍
Vulnerability Scanning

Continuous dependency scanning, SAST on every commit, and quarterly DAST scans. CVEs triaged within 24 hours of disclosure.

Responsible Disclosure

Found a vulnerability? Tell us first.

We take security reports seriously. If you discover a security vulnerability in Clinit, please report it to our security team before disclosing publicly. We commit to acknowledging reports within 24 hours and resolving critical issues within 48 hours.

Email: security@clinit.app
PGP key available on request
No legal action for good-faith reports
We credit researchers in our changelog
Report a Vulnerability →
Critical (RCE, auth bypass)
Fix SLA: 48 hours
High (data exposure, privilege esc.)
Fix SLA: 7 days
Medium (XSS, CSRF)
Fix SLA: 30 days
Low (info disclosure)
Fix SLA: 90 days
Documentation

Compliance documents available on request

We provide all documentation your legal or compliance team needs. Contact us with your request.

HIPAA
Business Associate Agreement

Standard BAA for all US/international clinics handling PHI. Counter-signed by Clinit within 1 business day.

Request document →
GDPR
Data Processing Agreement

GDPR-compliant DPA defining our role as Data Processor and your rights as Data Controller.

Request document →
SOC 2
SOC 2 Type II Report

Full audit report from our independent CPA firm. Available under NDA to enterprise clients.

Request document →
Security
Security Questionnaire

Pre-filled CAIQ/VSA questionnaire for enterprise procurement processes and insurance assessments.

Request document →
Infra
Sub-processor List

Complete list of sub-processors (Supabase, Vercel, Resend, Paymob) with their own compliance details.

Request document →
Pentest
Penetration Test Summary

Executive summary of our most recent third-party pentest. Full report available to enterprise clients.

Request document →
Get Started Securely

Your clinic data deserves enterprise security

All Clinit plans include full compliance coverage — HIPAA, PCI, SOC 2, and GDPR are not add-ons. Security is built in from day one.

Start Free Trial →Request Compliance Docs