Security at Goclinicbox
Clinics trust us with their most sensitive data — patient records. Here's how we protect it.
All traffic is encrypted with TLS in transit. Passwords and sensitive credentials are hashed/encrypted at rest, never stored in plain text.
Every staff member gets an individual login. Receptionists, nurses, pharmacists and doctors each see only what their role needs — clinics control the permissions.
Every clinic's data is scoped and isolated at the database level — one clinic can never see another clinic's patients, staff or records.
Patient portal and booking-page logins are OTP-verified. Staff sessions expire automatically after inactivity.
Clinic and patient data is backed up regularly so a hardware fault never means lost records.
Consent capture at booking, purpose limitation, and data export/erasure workflows are built into the product to help your clinic meet its obligations under India's DPDP Act, 2023.
Card and UPI payments are handled by regulated payment gateways — we never store your patients' card numbers.
We take security reports seriously and investigate every one raised in good faith.
We welcome responsible disclosure. Report issues to [email protected] — we take every report seriously.