Security

Security that's enforced, not promised.

The controls below are enforced by the platform itself, on every request, whether it comes from our app or not.

Tenant isolation in the database

Every record belongs to one organization, and the database itself refuses reads and writes across organizations, not just the application.

Least-privilege roles

Permissions are granted by role and scoped to locations. The server checks every request; hiding a button is never the control.

Append-only audit trail

Access decisions and changes are recorded in an audit log that cannot be edited or deleted, including refused attempts.

Encryption of sensitive fields

Sensitive identifiers are encrypted at the field level with keys kept outside the application code.

No card data on MOD servers

Payment details are entered into the payment provider's own secure fields. MOD never sees or stores card numbers.

Separation of duties

MOD staff who manage subscriptions have no access to patient records. Clinical approvals are human-only.

When payments fail

Your records are never held hostage.

A failed payment starts a grace period with full access. After it, your practice can still read and export every record. MOD never cuts a practice off from its own data.

Questions from your compliance team?

We'll walk them through how MOD handles access, audit and data.