Trust & security

Your patients’ data, and exactly who can touch it

You are about to put medical records, passports and payment details into someone else’s software. That deserves specifics rather than reassurance. Here is where the data sits, who can reach it, what we have built to protect it — and what we have not built yet.

The short version

Your data lives in a managed PostgreSQL database in US West — San Francisco, California. Every record is scoped to your agency, so no other agency can reach it. Passwords are hashed, connections are encrypted, two-factor is available, and every change is written to an audit log you can read. Our support staff can enter your CRM to help you — that access is limited to named accounts, logged in your audit log and shown as a banner while it happens. You can export your data at any time without asking, and cancel without penalty. We hold no third-party security certifications, and we say so below rather than leave you to find out.

Where it lives

One region, one database, one owner per record

Region

US West — San Francisco, California

Platform

Railway, managed PostgreSQL

Replication

Not copied to other regions

Your agency's data is stored in a managed PostgreSQL database in Railway's US West region, in San Francisco. It is not copied to other regions, and it is not shared with any other agency's database schema.

Access

Who can see your patients

The honest answer, including the part most vendors leave out.

Your own team

Whatever their role and permissions allow. Admins see everything in your agency; agents see the patients assigned to them. A mailbox or WhatsApp number an agent connects as personal is visible only to that agent. You control this, and you can change it at any time.

Our platform administrators

A named platform administrator can enter your agency's CRM to investigate a problem — this is how we answer a support request we cannot reproduce. It is restricted to specific accounts, it is written to your audit log the moment it starts, and a banner is displayed for the whole session. We will not pretend this access does not exist: any SaaS whose staff can help you with your data has it, and the ones claiming otherwise usually have it too.

Nobody else

Your data is not sold, not shared with other agencies, not used to train any model, and not given to advertisers. There is no analytics product built on top of your patients.

Controls

What protects it

Each of these is in the product today and visible to you inside it.

Every record belongs to one agency

Tenant isolation is not a setting — it is how every query in the application is written. Each record carries the id of the agency that owns it, and every read and write is filtered by the agency of the person making the request. There is no screen, export or API route that returns another agency's patients.

Encrypted in transit

Every connection to the CRM, the patient portal and the chat widget is served over TLS. The app sends HSTS, so a browser that has visited once will refuse to connect over plain HTTP afterwards.

Passwords are never stored

Passwords are hashed with bcrypt and never written down in a form anyone — including us — can reverse. A stolen database row does not yield a password.

Two-factor authentication

Any user can turn on TOTP two-factor authentication with an authenticator app. Both the password and the second factor are rate limited, so neither can be guessed by repetition.

Roles, and exceptions to roles

Admin, manager and agent each see a different slice of the CRM, and an agent sees only the patients assigned to them. Individual permissions can be granted or revoked per person on top of their role, so access can be shaped to the actual job rather than the nearest label.

Everything is written down

Every create, update and delete is recorded in an audit log with who did it, when, and what changed — including logins and including our own support access. You can read your agency's audit log yourself, at any time, from inside the CRM.

Connected accounts are encrypted

When you connect an email provider, a mailbox, a WhatsApp number or an Instagram account, the keys, passwords, cookies and sign-in tokens that let the CRM act on it are encrypted before they are stored, and are only decrypted inside the service that holds the connection. They are never shown again, not even to the person who entered them. The messages themselves are stored in your CRM like the rest of your patient records.

Brute force is throttled

Sign-in, two-factor codes and account creation are each rate limited. Limits are keyed so that an attacker guessing at one of your accounts cannot lock your own team out of it.

Your data

It is yours, and you can take it

Export it whenever you want

Your leads export to CSV from inside the CRM, with your custom fields included, without asking us and without a support ticket. It is your data and it leaves in a format any other system can read.

Leave whenever you want

Subscriptions are monthly or yearly with no lock-in period and no exit fee. Cancelling stops the next payment; your data stays reachable for export through the end of the period you have paid for.

Have it deleted

On request we permanently delete your agency and everything in it — patients, notes, files, finance records — and confirm when it is done. This is currently a request rather than a button you press yourself; we would rather tell you that than imply a self-service control we have not built.

Correct it

Every field on a patient record is editable by your team, and the change is recorded in the audit log. You never need us to fix your own data.

European data protection

GDPR, for an agency with European patients

Most medical tourism agencies treat patients who live in the European Union, which puts the GDPR squarely in scope — and health data is a special category under it, held to a higher standard than an ordinary customer list.

You are the controller, we are the processor

Your agency decides what patient data to collect and why; we store and process it on your instructions and for no purpose of our own. That is the relationship the GDPR describes, and it means the obligations to your patients sit with you while the obligations to keep it safe sit with us.

Your data is in the United States

We host in San Francisco, so data about EU residents leaves the EU. We say so plainly because a transfer you were not told about is the problem, not the transfer itself. If EU-only residency is a requirement for your agency, tell us before you subscribe rather than after — we would rather lose the sale than have you discover it later.

Data minimisation is built in, not bolted on

The CRM asks for the fields a medical tourism agency actually needs and does not invite you to collect more. Clinical intake questions are yours to define per procedure, so you can gather what a surgeon needs to assess suitability and nothing further.

Subject access, in practice

When a patient asks what you hold about them, everything is on one record and exports in a readable form — so answering them is a few minutes of work rather than a search across systems.

This page describes how the product works. It is not legal advice, and it does not decide whether your own processing is lawful — that depends on what you collect, why, and what you tell your patients. If you need a signed data processing agreement, ask us.

Compared

The practices the big platforms use, and whether we use them

Measured against Salesforce, Zoho, HubSpot and Odoo — the platforms an agency usually compares us with.

Security practices compared with major CRM platforms
PracticeUsMajor platforms
Encryption in transit (TLS) everywhere
Passwords hashed, never stored in the clear
Two-factor authentication available
Role-based access control
Per-user permission overrides
Full audit log of create, update and delete
Admin access to customer data is logged
Self-service data export
Tenant data isolated per customer
Brute-force rate limiting on sign-in
No customer data used to train modelsSeveral large platforms now reserve the right to use customer content for AI features. We do not, at all.

This compares security practices, not certifications. Where the large platforms are ahead of us is set out in the next section rather than hidden in a footnote.

Straight answers

What we do not have

A trust page that lists only strengths is marketing. This is the part you can hold us to.

We are not SOC 2 or ISO 27001 certified

Those are independent audits that cost real money and take months, and we have not done them. Salesforce, HubSpot, Zoho and Odoo have. If your agency's procurement requires a certification, we are not the right supplier today and we will tell you so rather than waste your time.

We do not sign HIPAA business associate agreements

HIPAA governs US healthcare providers and their vendors. If you handle US patient records under HIPAA, you need a vendor who will sign a BAA. We do not.

We have not had an external penetration test

The security controls on this page are real and you can verify them in the product, but they have not been probed by an independent firm.

Questions

Security questions, answered

Can you see my patients' data?

+

A named platform administrator can enter your CRM to investigate a support problem. It is restricted to specific accounts, written to your audit log the moment it starts, and shown as a banner for the whole session, so you can see every time it happens. Outside of that, no — your data is not read, sold, shared between agencies, or used to train any model.

Where is my data stored?

+

In a managed PostgreSQL database in Railway's US West region, in San Francisco, California. It is not replicated to other regions.

We have European patients. Is that a problem?

+

It means an international data transfer, because we host in the United States. We state that plainly so you can make the decision with the facts. Your agency is the data controller and we are the processor; if EU-only residency is a hard requirement for you, tell us before subscribing.

Can another agency see my patients?

+

No. Every record carries the id of the agency that owns it, and every query in the application filters by the agency of the person making the request. There is no screen, export or API route that returns another agency's data.

What happens to my data if I cancel?

+

Cancelling stops the next payment. Your data stays reachable so you can export it through the end of the period you have already paid for. On request we permanently delete your agency and everything in it and confirm when it is done.

Can I get my data out?

+

Yes, at any time, without asking us. Leads export to CSV from inside the CRM with your custom fields included.

Are you SOC 2 or ISO 27001 certified?

+

No. Those are independent audits we have not undertaken. The controls described on this page are real and verifiable inside the product, but they have not been certified by a third party. If your procurement requires a certification, we are not the right supplier today.

Will you sign a HIPAA business associate agreement?

+

No. HIPAA governs US healthcare providers and their vendors, and we do not sign BAAs. If you handle US patient records under HIPAA, you need a vendor who will — we would rather say so now than after you have migrated.

Have you had an external penetration test?

+

No. The controls described on this page are real and you can verify each one inside the product, but they have not been probed by an independent security firm.

Do you use our data to train AI?

+

No. Your patients, notes and documents are not used to train any model, ours or anyone else's. Where the CRM offers an AI assist, it acts on the specific record in front of you at that moment and the content is not retained for training.

Is my data encrypted?

+

Every connection is encrypted with TLS, and we send HSTS so browsers refuse to fall back to plain HTTP. Passwords are hashed with bcrypt, and the credentials of anything you connect — your email provider's API key, mailbox passwords and sign-in tokens, WhatsApp and Instagram sessions — are encrypted before storage.

What happens if there is a breach?

+

We would tell you, promptly and directly, with what we know and what we do not yet know. As your processor under the GDPR, notifying you without undue delay is our obligation and your notifications to your own patients depend on it.

Who has access inside your company?

+

Platform administration is limited to named accounts, configured by email address in the server environment rather than as a database flag — so nobody can grant themselves platform access by editing a record.

Can I see who accessed a record?

+

Yes. Your audit log is in the CRM and shows every create, update and delete with who did it and when, including logins and including our support access.

Still have a question we have not answered?

Security questions get a direct answer from someone who knows the system, not a brochure. If the answer is “we do not do that”, you will be told.