Security
Clinic data security and KVKK compliance: care at every layer.
Clineo treats security not as a single feature but as a layered approach in which identity, permissions, data access, infrastructure and operational processes work together.
Security layers
Role and permission management
Manage which modules users can see and act on according to their roles.
Clinic data separation
Each clinic workspace is separated in a tenant context; users can only access the clinic data they’re authorized for.
Secure sessions
JWT-based sessions are verified on the server along with user and clinic status.
Encryption of selected fields
Selected critical identity fields such as national ID number and phone are protected at the application level using AES-GCM.
IP restriction
With the Clineo Enterprise plan, you can limit account access to networks you specify.
API key security
API keys for enterprise connections are stored as hashes instead of plain text.
Media access control
X-rays and clinical photos aren’t served directly from a public folder.
Backup approach
Planned database and media backup policies support clinic continuity.
Organizational controls
Limit permissions, make activity visible.
The clinic owner can set staff roles, module permissions and the access approach according to the organization’s structure.
Identity
User accounts, secure passwords and session verification.
Permissions
Controlled access at the role, module and action level.
Trail
Audit and operational logs for critical actions.
Continuity
Backups, health checks and a disaster recovery approach.
Let’s look together
How would your clinic work with Clineo?
Let’s plan a short product walkthrough tailored to your specialty and team.