Security at Goclinicbox

Clinics trust us with their most sensitive data — patient records. Here's how we protect it.

Encryption everywhere

All traffic is encrypted with TLS in transit. Passwords and sensitive credentials are hashed/encrypted at rest, never stored in plain text.

Role-based access

Every staff member gets an individual login. Receptionists, nurses, pharmacists and doctors each see only what their role needs — clinics control the permissions.

Multi-tenant isolation

Every clinic's data is scoped and isolated at the database level — one clinic can never see another clinic's patients, staff or records.

OTP-verified access

Patient portal and booking-page logins are OTP-verified. Staff sessions expire automatically after inactivity.

Backups

Clinic and patient data is backed up regularly so a hardware fault never means lost records.

DPDP-minded design

Consent capture at booking, purpose limitation, and data export/erasure workflows are built into the product to help your clinic meet its obligations under India's DPDP Act, 2023.

Payments

Card and UPI payments are handled by regulated payment gateways — we never store your patients' card numbers.

Responsible disclosure

We take security reports seriously and investigate every one raised in good faith.

Found a vulnerability?

We welcome responsible disclosure. Report issues to [email protected] — we take every report seriously.