All data in transit is protected by TLS 1.2+. WhatsApp tokens are encrypted at rest using AES-256-GCM.
Every clinic's patients, messages, and appointments are logically isolated. No cross-clinic data access is possible.
All inbound Meta webhook payloads are verified using HMAC-SHA256 with your App Secret before processing.
Passwords hashed with bcrypt. JWT tokens with 7-day expiry. Rate limiting on all login endpoints.
All AI actions, appointment changes, and staff logins are logged with timestamps for audit trail.
All API endpoints are rate-limited. Auth endpoints have stricter limits (20 req/15 min). Webhook replay attacks are mitigated by Meta's delivery deduplication.
HttpOnly, Secure, SameSite=LaxX-Hub-Signature-256 header using your Meta App Secret before any processing occursIn the event of a security incident affecting personal data:
We welcome responsible disclosure from security researchers. If you discover a vulnerability in our platform, please report it to us before making it public so we can fix it first.
Email: security@doctorsmyagency.com
Please include a description of the vulnerability, steps to reproduce, potential impact, and any proof-of-concept (non-destructive only). We will acknowledge your report within 3 business days and aim to resolve confirmed issues within 30 days.
We do not take legal action against researchers who follow responsible disclosure guidelines. We do not offer a bug bounty programme at this time but will publicly credit researchers who request it.
We use the following security-critical third-party services:
All sub-processors are evaluated for security posture before integration.