Security
Last updated: May 28, 2026
Protecting clinic and patient data is core to CliniqHQ. This page summarizes the security measures we use to safeguard the platform. For privacy practices, see our Privacy Policy.
1. Infrastructure
- Hosted on Google Cloud with managed services and regional deployment options
- Network isolation between application tiers
- Automated backups and disaster recovery procedures
- DDoS protection and Web Application Firewall at the edge where configured
2. Application security
- HTTPS/TLS encryption for all client and API traffic
- JWT-based authentication with separate access and refresh tokens
- Role-based access control (RBAC) for clinic staff
- Multi-tenant data isolation at the application and database layer
- Input validation and protection against common web vulnerabilities
- Rate limiting on public API endpoints
3. Data protection
- Encryption at rest for sensitive credentials (including third-party OAuth tokens)
- Hashed storage of user passwords using industry-standard algorithms
- Audit logs for administrative and clinical actions where enabled
- Principle of least privilege for internal system access
4. Integrations
Optional integrations (Google Calendar, SMS, email, AI providers) use OAuth or API keys stored securely. Clinics can disconnect integrations at any time. Google Calendar access is limited to appointment event sync — see our Privacy Policy for details.
5. Monitoring and incident response
- Centralized logging and alerting for production systems
- Documented incident response process
- Notification to affected clinics in the event of a confirmed data breach, as required by law or contract
6. Development practices
- Code review and automated testing before production deployment
- Secrets managed via Google Secret Manager — not stored in source code
- Separate development and production environments
7. Your responsibilities
Security is a shared responsibility. Clinics should use strong passwords, limit staff access to appropriate roles, enable clinic policies for device security, and promptly report suspicious activity to security@cliniqhq.com.
8. Report a vulnerability
If you believe you have found a security issue, please report it responsibly to security@cliniqhq.com. Do not publicly disclose vulnerabilities before we have had a reasonable opportunity to investigate.