Skip to content

Sign in to your clinic

Each clinic signs in at its own address.

.conphident.live
ConphiDent staff sign in
Book a demo

Security

Patient data deserves a straight answer.

What protects your clinic's records, as the code does it today, and what we do not claim.

Controls in the product

What protects your clinic's data.

Every record belongs to one clinic

Every record carries the clinic it belongs to, and the product's reads and writes are scoped to one clinic. A separate check reviews the database queries that search or change records and reports any that is not scoped.

Roles, checked on the server

Nine staff roles and twenty-two permissions, checked on the server, never in the browser.

WhatsApp keys stay encrypted

Meta credentials are encrypted (AES-256-GCM), used only on the server, and never sent to a browser.

Every message from Meta is verified

Webhook calls are signature-checked before anything is read. A call that fails the check is refused.

Who sees what

A login for each person, a role for each job.

Front desk, dentists, billing, stock and auditors each see the work their role needs.

  1. A role for each job Front desk, dentist, billing, stock or auditor: each login sees the work its role needs, and money stays with the roles that handle it.
  2. Switch off, keep the record Switching a login off stops it signing in, and everything that person wrote stays on the record.
Interface illustration · fictional clinic and patients

How a request is checked

Five checks, in this order, on a signed-in request.

  1. Check 1

    Session

    401

    Signed in, and not owing a password change.

  2. Check 2

    Role

    403

    The person's role holds the permission this needs.

  3. Check 3

    Module

    403

    The clinic has that part of the product switched on.

  4. Check 4

    Clinic

    no rows

    Queries are scoped to your clinic, so another clinic's record is not returned.

  5. Check 5

    Record

    kept

    Sensitive actions are written to the audit log: who, what and when.

Accounts and files

The details underneath.

Signing in
Each person signs in with their own account. Sessions are checked on the server on every request.
Passwords
At least 12 characters, with upper and lower case and a number.
Wrong passwords
Five wrong passwords lock the account for 15 minutes.
Resetting
Reset links are single-use and expire in 30 minutes.
Forced change
An administrator can make someone change their password at their next sign-in.
Clinical files
X-rays and clinical documents sit in private storage, reached only through short-lived signed links.

Being straight with you

What we do not claim.

No certification claims
We do not hold or claim ISO 27001, SOC 2, HIPAA certification or regulatory clearance. If a certification matters to your practice, ask us where we are before you buy, not after.
No clinical claims
ConphiDent does not diagnose, does not make autonomous clinical decisions and does not claim diagnostic accuracy. Clinical judgement remains with your qualified team.
Demonstration data is fictional
Every example, patient name and figure shown across this site is invented for demonstration. None of it comes from a real clinic.

Ask us the hard ones.