Security
Last updated September 30, 2026
Clinics trust us with their patients' names and numbers. Here is exactly how we protect them.
We collect almost nothing
First names and mobile numbers. No health information, no treatment details, no contact lists. The less we hold, the less there is to protect.
No texts from us
Invites are sent from the patient's own phone. Clinvite has no texting system that could be abused to message your patients.
Safeguards
- Encryption in transit (HTTPS everywhere, HSTS) and at rest.
- Passwords stored as salted PBKDF2 hashes, never in plain text. Sessions use secure, HTTP-only cookies.
- Every clinic's data is separated by account. Every request is checked against the signed-in user's clinic and role. Automated tests confirm one clinic can never read another's data.
- The public pages can only read a clinic's name and offer. They cannot list or read any patient record.
- Front-desk staff see only their own location.
- Rate limits and optional bot checks on every public form.
- An audit log records sign-ins, settings changes, visit scans, exports and deletions.
- Strict browser security headers, including a content security policy and no framing.
- Records with no activity for 24 months are deleted automatically.
Sub-processors
| Provider | Purpose |
|---|---|
| Cloudflare, Inc. | Hosting, database, network security |
| Resend | Email to clinic staff |
| Stripe, Inc. | Billing |
Report a problem
Found a security issue? Email hello@clinvite.ca with "Security" in the subject. We respond within one business day.