Trust Center

Security & Data Practices

The controls and operating practices MedSpaOS uses to protect clinic, staff, and patient information. Product configuration and customer agreements determine which controls apply to a specific deployment.

Last updated: September 2, 2026

Security by design

MedSpaOS uses a shared application with tenant-aware routing and authorization. Access is limited by account role and, where enabled, clinic device and network controls. We use least-privilege access for operational systems and review permissions as the product evolves.

Data protection

Data is transmitted over encrypted connections and stored using the protections provided by our hosting and database providers. Supabase PostgreSQL Row Level Security, tenant relationships, authentication, and audit events are used to reduce unauthorized cross-clinic access. Encryption, backup, and retention details are subject to the applicable infrastructure configuration and customer agreement.

Application and infrastructure security

We use code review, dependency updates, security headers, secret-management practices, logging, monitoring, and automated security checks as appropriate to the service. Access to production systems is restricted to authorized personnel and service accounts. We do not publish sensitive architecture details that could make the service easier to attack.

Incident response

We maintain processes to detect, investigate, contain, and recover from security incidents. We will notify affected customers without undue delay when required by law or contract and will provide information reasonably needed for customers to meet their own notification obligations.

Customer responsibilities

Customers must use strong, unique credentials, configure roles conservatively, remove departing users, protect exported records, validate integrations, and report suspected vulnerabilities or incidents promptly. Clinics remain responsible for their patient notices, consent, legal basis, retention schedule, and clinical safeguards.

Report a vulnerability

Send responsible security reports to security@medspaos.com. Please include enough detail to reproduce the issue and avoid accessing, changing, or deleting data that does not belong to you. We aim to acknowledge reports promptly and coordinate a fix or mitigation.

This page is provided for product and operational transparency. It is not legal advice. Have qualified counsel review the applicable agreement before relying on it in a live service.