Legal and trust

Security

How CliniFlows protects private pathway work, temporary document imports, and publication boundaries.

Last updated 8 August 2026 Draft under legal review

Our approach

CliniFlows treats pathway ownership, review state, and publication visibility as security-sensitive product state. Documents used to build pathways are temporary processing inputs and are deleted after processing.

Authentication and access

Authentication uses server-managed sessions. Workspace and pathway permissions are checked on the server and reinforced with database row-level security. Access is scoped to the user, workspace, organisation, and publication context required for the action.

Database and temporary storage

Pathway and governance records are stored in Supabase Postgres with row-level security policies. Documents used to build pathways are held in private temporary storage only while processing, then deleted together with extracted text and upload metadata.

Application safeguards

CliniFlows validates important inputs at application boundaries, keeps privileged operations on the server, and separates draft authoring from approved publication. Review, version, owner, and visibility state remain explicit so changes do not silently replace an approved pathway.

Customer responsibilities

Customers should assign the minimum workspace access needed, review publication visibility before sharing, remove access when roles change, and avoid uploading patient-identifiable records or other content the workspace is not authorised to hold.

Report a security concern

Report suspected vulnerabilities, unauthorised access, or security incidents to support@cliniflows.co.uk. Include enough information to investigate, but do not send patient-identifiable data, passwords, authentication codes, or active credentials by email.

Assurance status

This page describes the controls currently represented in the product and architecture. CliniFlows does not claim certifications, audit reports, or regulatory approvals that have not been independently completed and confirmed.