Security

Security and Data Protection

Zenome uses layered safeguards to protect clinic information, control access, secure payments, and keep every clinic's workspace separated.

1. Encryption and Secure Connections

Zenome uses encrypted HTTPS connections to protect information while it travels between a user's device and the application.

Production data is stored on managed infrastructure that provides encryption at rest, helping protect stored information from unauthorized access.

2. Separated Clinic Workspaces

Each clinic operates in its own workspace. Clinic data is scoped to that clinic and is not shared across clinics.

Public booking is connected to each clinic's domain and booking context, so booking requests stay tied to the correct clinic.

3. Secure Account Access

Accounts are protected with secure sign-in, password reset, and session controls designed to keep clinic access limited to authorized users.

Clinic owners should give each team member their own account and remove access promptly when a staff member no longer needs it.

4. Role-Based Access Controls

Staff access is restricted to the clinic account and permissions assigned to that user. Sensitive owner and administrative areas are not available to every staff role.

This approach helps clinics give team members the access they need without exposing unrelated administrative controls.

5. Protected Payment Processing

Card and in-person Terminal payments are processed through Stripe. Zenome does not expose full card numbers to clinic staff.

Payment status and transaction references are retained only as needed to support clinic billing, receipts, refunds, and reconciliation workflows.

6. Operational Safeguards

Zenome uses controlled production access, environment separation, and activity records for important clinic and payment workflows.

Managed hosting and database services provide infrastructure monitoring, recovery capabilities, and backups designed to support service continuity.

7. Clinic Responsibilities

Security is shared. Clinics should use strong unique passwords, keep account access current, verify payment actions, and avoid sharing private client information through unsecured channels.

Team members should sign out of shared devices and keep browsers, computers, and payment readers updated and physically secure.