Enterprise-Grade Security for Healthcare Data
Your hospital and consultant data deserves the highest level of protection. ConsultPro is built security-first with encryption, isolation, and compliance at every layer.
AES-256
Encryption
Tenant
Isolation
SOC 2
Ready
HIPAA
Aligned
RBAC
Enforced
JWT
Auth
How We Protect Your Data
Built secure from the ground up
Layered safeguards across infrastructure, access, and data protect every hospital and consultant on the platform.
Multi-Tenant Data Isolation
Every organization's data is completely separated at the database level. Hospital A can never access Hospital B's data, and no consultant can see another consultant's billing.
- Tenant-scoped database queries enforced at the ORM level
- Row-level security policies on all tables
- Separate encryption keys per tenant
- Tenant context validated on every API request
- Cross-tenant data leakage prevention audits
Role-Based Access Control
Fine-grained permissions ensure every user sees only what they need. Admins, staff, and consultants each get a tailored experience with appropriate access levels.
- Hospital Admin: full access to hospital data and settings
- Hospital Staff: visit logging, billing submission, limited reports
- Consultant Admin: own billing, earnings, TDS certificates
- Consultant Staff: view-only access to visit schedules
- Custom roles available on Enterprise plans
JWT Authentication with Refresh Tokens
Secure token-based authentication with short-lived access tokens and rotating refresh tokens. Sessions are managed securely without storing sensitive data in cookies.
- Access tokens expire in 15 minutes
- Refresh tokens rotate on every use
- Token revocation on password change or logout
- Secure HTTP-only cookie storage
- Device-level session management
Account Protection
Automated brute-force prevention locks accounts after repeated failed login attempts. Combined with rate limiting and suspicious activity detection.
- Account locked after 5 consecutive failed attempts
- Automatic unlock after 30-minute cooldown
- Admin notification on repeated lock events
- IP-based rate limiting on authentication endpoints
- Suspicious login location alerts
256-Bit Encryption
All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Sensitive fields like PAN numbers and bank details receive additional field-level encryption.
- AES-256 encryption for data at rest
- TLS 1.3 for all data in transit
- Field-level encryption for PAN, bank details, and contact info
- Encryption key rotation every 90 days
- Hardware security module (HSM) for key management
SOC 2 Compliance Readiness
ConsultPro is built with SOC 2 Type II compliance in mind. Our security controls, audit logging, and operational procedures align with the Trust Services Criteria.
- Comprehensive audit logging for all user actions
- Change management procedures for code deployments
- Incident response plan with defined escalation paths
- Vendor security assessments for third-party integrations
- Annual penetration testing by independent auditors
HIPAA-Aligned Practices
While ConsultPro is built for the Indian healthcare market, our security practices align with HIPAA standards for handling protected health information.
- Minimum necessary access principle enforced
- Audit trail for all data access and modifications
- Business Associate Agreements available for US clients
- Data retention and disposal policies
- Employee security training and background checks
Have Security Questions?
Our team is happy to discuss our security architecture, compliance posture, and data handling practices in detail.