Clinitricks — AI-Led Clinic Management

Security & privacy

Your patients' data,
treated like it's yours.

Clinitricks was designed around the DPDP Act (India) and HIPAA (US) from day one — not bolted on after. Sensitive fields are encrypted, every action is logged, access is role-based, and you can walk away with all your data at any time.

We say "designed for", never "certified for". A formal SOC 2 audit is on our roadmap — until it's done, we won't display a badge we haven't earned.

How we protect it

A DPDP- and HIPAA-aligned framework, in plain terms.

Encryption at rest

Sensitive patient fields — phone, email, health IDs, allergies and more — are encrypted with AES-256 in the database, not stored as plain text. In transit, everything moves over 256-bit TLS.

Tamper-evident audit trail

Every create, view, edit and delete on patient data is written to an append-only audit log. If something changes, there's a record of who, what and when — designed so the trail can't be quietly rewritten.

Role-based access

Doctors, admins and receptionists each see only what their role needs. Access is checked on every request, and a break-glass path exists for genuine emergencies — always logged.

Digital consent capture

Register the patient, then capture consent with real, trackable links — on the device, over WhatsApp, or printed. Consent is recorded against the patient, so you always know what was agreed and when.

Sign-in hardening

Multi-factor authentication, session fingerprinting and rate-limited login protect accounts from takeover and brute-force attempts — without making the day-to-day sign-in painful.

Export anytime · no lock-in

Your data is yours. Export your tenant's records whenever you like, and exercise right-to-erasure when a patient asks. Cancel and leave with everything — we never hold your data hostage.

Where we stand — no overclaiming

DPDP Act (India) Designed to align

Consent, purpose-limitation, right-to-erasure and audit are built into how patient data is handled.

HIPAA (US) Designed to align

Access controls, encryption, audit logging and minimum-necessary access follow HIPAA's Security Rule principles.

SOC 2 On the roadmap

A formal third-party audit is planned. Until it's complete, we make no SOC 2 claim and display no badge.

"Designed to align" means our architecture follows these frameworks' principles. It is not a certification or a guarantee of legal compliance — your clinic remains the data controller and is responsible for its own regulatory obligations.

You are the data controller — we process on your behalf
Minimum-necessary access, enforced per role
Encryption in transit (TLS) and at rest (AES-256)
Payments handled by Razorpay — we never store card numbers
Every patient-data action written to the audit log
Right-to-erasure and tenant data export built in

Questions about security or a vulnerability to report?

We take responsible disclosure seriously. Reach the team and we'll respond — and if you're evaluating Clinitricks for a clinic, we're happy to walk through our data-handling in detail.