Security

What the software actually does

No seals, no badges, no certification logos. Below is the list of controls DocOS implements, described in enough detail that you can check them.

Per-practice isolation

Each practice gets its own application and its own database. Nothing is shared between practices, so one practice seeing another's patients is not unlikely — it is impossible by construction.

An audit record that cannot be rewritten

Once written, an audit entry cannot be edited or deleted after the fact. That includes entries about administrators.

Reads are logged, not just changes

You can answer who opened a patient's information, and when. Most practices cannot answer that question at all.

Two-factor authentication, built in

Nobody shares a login. An administrator can never act as another person — they can grant access, not impersonate.

Encryption at rest

Stored data is encrypted at rest, and access to it runs through the same audited paths as everything else.

Nightly backups that report their own failure

Backups run nightly, and the system tells you when a backup has stopped running. A silent backup is the one that fails you.

Deliberately few dependencies

DocOS is built on a small set of software dependencies. A smaller attack surface is a security property, not a preference.

AI assistance is off unless you turn it on

Optional AI features are disabled by default. When a practice turns them on, patient information is stripped before anything is analysed.

On compliance, plainly

Compliance is a property of your practice's whole program — your policies, your training, your vendors and how your people actually behave. It is not a property of any single piece of software, and no certification exists that would make it one. We will not tell you DocOS makes you compliant.

What we will tell you is exactly what the software does, so your program can account for it. A business associate agreement is part of onboarding. DocOS does not provide legal or regulatory advice.

Two limits worth stating

  • DocOS decides nothing clinical. The bundled procedure and diagnosis code sets are drafts that your practice verifies. Every clinical outcome names a provider as the decider.
  • Patient-facing summaries are constrained by construction. They are built so they cannot contain procedure codes, diagnosis codes, provider identifiers, record numbers or insurance IDs.