Back

Security and trust

Draft, under review. Version 0.3-draft.

Kinetta handles health information, so security is treated as a product requirement rather than an afterthought. This page describes the approach in general terms.

Security governance

Named people are accountable for security, privacy and clinical safety. Security and privacy requirements are written into features before they are built.

Access control

  • Password sign-in is protected by a one-time verification code sent by email.
  • Google sign-in is available as a separate account access method.
  • Every request is checked on the server against authorization rules.
  • Clinics are separated from one another.

Encryption

Information is encrypted in transit using TLS, and encrypted at rest by the hosting platform.

Reporting a security problem

Responsible disclosure

If you believe you have found a security issue, please report it to [SECURITY EMAIL].