Your patients' records are sensitive. Here's what actually happens under the hood — not marketing claims, but how the system is built.
Every record in ClinaFix — patients, visits, treatment plans, staff — is scoped to your clinic's account at the database level. Every read and write is checked against clinic ownership before it happens, so one clinic's data is never visible to another.
Staff accounts carry a role (admin, attending doctor, front desk, etc.) and, for multi-branch accounts, a specific location assignment — someone at Branch A doesn't see Branch B's patients unless explicitly given access.
Passwords are hashed, never stored in plain text. Third-party tokens (like a connected Google Calendar) are encrypted at rest, separately from the rest of your data.
ClinaFix runs on Vercel and Neon (PostgreSQL) — the same infrastructure providers used by a large share of production SaaS applications, with encryption in transit and at rest as standard.
Code and database changes go through an isolated staging environment — a full clone of the data model with no connection to live clinic data — before reaching production.
Your patients' records belong to your clinic, not to ClinaFix. Exports are available on request, and deleting your account removes your data per our retention policy.
Have a specific security or compliance question for your clinic's own requirements? Contact us — we're happy to answer directly.