Security that's enforced, not promised.
The controls below are enforced by the platform itself, on every request, whether it comes from our app or not.
Tenant isolation in the database
Every record belongs to one organization, and the database itself refuses reads and writes across organizations, not just the application.
Least-privilege roles
Permissions are granted by role and scoped to locations. The server checks every request; hiding a button is never the control.
Append-only audit trail
Access decisions and changes are recorded in an audit log that cannot be edited or deleted, including refused attempts.
Encryption of sensitive fields
Sensitive identifiers are encrypted at the field level with keys kept outside the application code.
No card data on MOD servers
Payment details are entered into the payment provider's own secure fields. MOD never sees or stores card numbers.
Separation of duties
MOD staff who manage subscriptions have no access to patient records. Clinical approvals are human-only.
Your records are never held hostage.
A failed payment starts a grace period with full access. After it, your practice can still read and export every record. MOD never cuts a practice off from its own data.
Questions from your compliance team?
We'll walk them through how MOD handles access, audit and data.