What we process, and what we deliberately do not

Clinesta is designed not to process patient data. That is not only a commitment: it is enforced by the data model, the form design, the upload rules and content detection.

Data processed

Account data
Name, email address, password hash and language preference. A password is never stored in plain text.
Workspace data
Clinic name, public website address, service and brand detail, and the sources you add.
Usage data
Audit runs, credit movements and security logs. IP addresses are hashed rather than stored raw.

Data we do not process

  • Patient identity information
  • Test and imaging results
  • Patient files and medical history
  • Identified or identifiable patient messages
  • Patient face photographs

Controls in place

Tenant isolation
Every query carries a workspace boundary and membership is verified server-side on every request. Hiding a menu item is not access control.
Crawler safety
The audit reads public addresses only. Local network, loopback and cloud metadata endpoints are blocked and re-validated at every redirect hop.
Session security
Session cookies are HttpOnly and SameSite; the session token is stored only as a hash.
AI providers
Only the necessary context is sent to a provider. When no provider is configured the product does not fake success; the feature is shown as unavailable.

Clinesta does not provide medical services, diagnosis or treatment advice. Generated content is a draft and must be reviewed by an authorized person before publication. Guard highlights potential risks but does not guarantee legal compliance.

Security contact

hello@clinesta.com

Clinesta shows no unverified certification badge. No SOC 2, ISO 27001 or HIPAA claim appears on this page before an independent audit is complete.

Start with the boundaries clear.

Security and Data Boundaries | Clinesta | Clinesta