Security
Last updated: June 25, 2026
Our approach
Security is a cross-cutting pillar in the design, development, and operation of the Kliniqo SaaS ecosystem. We apply industry-recognized best practices for cloud software to protect the information we handle and to ensure the availability of our digital products. This page describes, at a high level, the measures we have in place.
Cloud infrastructure
Our services are deployed on leading cloud infrastructure providers, with certified data centers located preferentially within the European Union. The architecture is designed to be scalable, redundant, and resilient against isolated component failures.
Encryption
Information is encrypted in transit using secure connections (HTTPS/TLS) between clients and our services. At rest, data stored in databases and file systems is protected using encryption mechanisms provided by the infrastructure providers we use.
Access control
Access to internal systems follows the principle of least privilege. Our technical team's access requires strong authentication and is segmented by environment (production, staging, and development). Sensitive credentials are managed through secure vaults, avoiding their exposure in code or uncontrolled channels.
Backups
We perform regular backups of critical data to reduce the risk of information loss in the event of an incident. Retention policies are adjusted to the operational needs of each service and are reviewed on an ongoing basis.
Updates and maintenance
The dependencies, libraries, and components used in our products are updated regularly, prioritizing updates that address known vulnerabilities. We apply code review and testing processes before deploying changes to production.
Audit and activity logging
Access to, and sensitive actions on, clinical data — logins, data exports, billing changes, file access — are recorded in a per-product audit log, with mechanisms that prevent an action from being attributed to a user other than the one who performed it.
Internal best practices
The Kliniqo team applies secure development best practices, configuration management, and change review. We promote a culture of continuous improvement in information security.
Reporting incidents
If you detect a possible security issue related to our services, you can report it to us at info@kliniqo.es. We will review the information provided and, if confirmed, take appropriate action.