1. Encryption and Secure Connections
Zenome uses encrypted HTTPS connections to protect information while it travels between a user's device and the application.
Production data is stored on managed infrastructure that provides encryption at rest, helping protect stored information from unauthorized access.
2. Separated Clinic Workspaces
Each clinic operates in its own workspace. Clinic data is scoped to that clinic and is not shared across clinics.
Public booking is connected to each clinic's domain and booking context, so booking requests stay tied to the correct clinic.
3. Secure Account Access
Accounts are protected with secure sign-in, password reset, and session controls designed to keep clinic access limited to authorized users.
Clinic owners should give each team member their own account and remove access promptly when a staff member no longer needs it.
4. Role-Based Access Controls
Staff access is restricted to the clinic account and permissions assigned to that user. Sensitive owner and administrative areas are not available to every staff role.
This approach helps clinics give team members the access they need without exposing unrelated administrative controls.
5. Protected Payment Processing
Card and in-person Terminal payments are processed through Stripe. Zenome does not expose full card numbers to clinic staff.
Payment status and transaction references are retained only as needed to support clinic billing, receipts, refunds, and reconciliation workflows.
6. Operational Safeguards
Zenome uses controlled production access, environment separation, and activity records for important clinic and payment workflows.
Managed hosting and database services provide infrastructure monitoring, recovery capabilities, and backups designed to support service continuity.
7. Clinic Responsibilities
Security is shared. Clinics should use strong unique passwords, keep account access current, verify payment actions, and avoid sharing private client information through unsecured channels.
Team members should sign out of shared devices and keep browsers, computers, and payment readers updated and physically secure.
