Legal

Security

How we think about protecting information as we build Practico.

This is a draft for owner and legal review. It distinguishes the inspected marketing-site source from requirements for a future clinic application; it is not a certification or a statement of deployed controls.

Marketing site: verified in source

The pilot form requests limited business-contact information and includes a warning not to submit patient or health information. Its source sends enquiries to a server route; the email-provider credential is read only on that server route. Repository inspection does not verify a deployment, provider configuration, transport encryption or live email delivery.

Future clinic application requirements

A future clinic application would need fact-specific design and verification for data minimization, least-privilege access, tenant isolation, auditability and correction history, encryption in transit and at rest, secure secret management, backup and restore, retention controls, vendor oversight and incident response. These are design requirements, not implemented controls.

Not verified or claimed

We do not claim compliance or certification under PHIPA or PIPEDA, SOC 2, ISO 27001, penetration testing, formal audits, Canadian-only storage, guaranteed security, or production protection of clinic data. Insurer connectivity remains roadmap work and externally dependent.

Reporting a concern

If you believe you've found a security issue, please let us know at security@practico.ca. Please do not send credentials or sensitive personal information.