Security Policy

Last updated: 12 May 2026

Patient data deserves serious protection. This page summarises the practical measures we apply today. We aim to evolve these controls as the platform matures.

What we do

  • Encrypted HTTPS connections for all traffic.
  • Access controls so a clinic's data is only available to members of that clinic.
  • Least-privilege access for staff roles and internal systems.
  • Authenticated access only — accounts require a password, and sensitive actions are gated.
  • Regular backups to support recovery.
  • Monitoring and logging of key actions where applicable.

Reporting a security issue

If you believe you have found a security issue, please email security@prescrio.app. We appreciate responsible disclosure and will not pursue legal action against good-faith research.