Legal
Security
How we keep clinic records private — in plain terms, without hand-waving.
Last updated 4 October 2026
On the phone
- The clinic's database on each phone is encrypted. Its key is sealed by the phone's secure hardware, so a lost, sold or repaired phone gives nothing away.
- Disabling a staff member, or signing a device out from the console, ends that device's access at once.
In transit and on our servers
- All traffic uses HTTPS. Our servers and database are in Singapore, and the database is encrypted at rest.
- Each clinic is isolated by the database itself, not just by our code: a query made on behalf of one clinic cannot return another clinic's rows. The server also refuses to run at all if it is ever connected with privileges that would bypass this.
- Passwords are stored only as Argon2id hashes. Repeated wrong passwords lock the account for a while, and sign-in attempts are rate-limited.
Our own access
- Our support team cannot open a clinic's account on its own authority. It files a request with a reason; the clinic owner is emailed and decides. Access, if approved, lasts a limited time and the clinic can end it at once.
- Support can look, never change — and the views it uses cannot show patient names, diagnoses or prescriptions.
- Every request and every visit is recorded and visible to the clinic in its console.
Payments
Card, UPI and bank details are entered on Razorpay's screen and never reach Sixo. Payments are verified by Razorpay's signature before a plan changes.
Reporting a problem
If you think you have found a security issue, please email kiranmarkad3@gmail.com with “Security” in the subject. We will acknowledge it within two working days and keep you informed while we fix it. Please do not access other people's data or disrupt the service.