soefer.Back to Soefer ↗
Legal & support
Terms of ServicePrivacy PolicyCancellation & RefundSecurityMedical DisclaimerContact Us
Home/Security
Legal & support +
Terms of ServicePrivacy PolicyCancellation & RefundSecurityMedical DisclaimerContact Us

Security

Last updated 29 September 2026

The architectural safeguards, cryptographic protocols, and operational procedures protecting user identity, queue integrity, and clinic workflows on Soefer.

On this page
Infrastructure & Data EncryptionStaff & Front-Desk Access BoundariesQueue Integrity & Public Display PrivacyDoctor KYC Verification & Document Auto-PurgeVulnerability Disclosure & Security Reporting

01Infrastructure & Data Encryption

In-Transit Protection: All network communications between mobile apps, clinic interfaces, and backend servers are strictly encrypted using Transport Layer Security (TLS 1.3) with perfect forward secrecy.

At-Rest Protection: Operational databases, appointment queues, and transaction ledgers are encrypted at rest using AES-256 transparent data encryption.

Domestic Data Residency: Central databases and synchronization services are hosted exclusively in secure domestic data centres located within India in compliance with the Digital Personal Data Protection Act (DPDP Act, 2023).

02Staff & Front-Desk Access Boundaries

Clinic front-desk personnel and receptionists operate under restricted Kiosk Mode permissions. Front-desk staff can verify tokens and announce turns, but are strictly prohibited from viewing doctor financial earnings, consultation notes, or account credentials.

The platform enforces strict privacy boundaries: clinic counter devices only receive the minimum pseudonymous queue details necessary for check-in, without storing patient phone numbers, dates of birth, or personal profile identifiers.

03Queue Integrity & Public Display Privacy

Our sequential token allocation engine guarantees queue integrity and eliminates duplicate token bookings between online patients and walk-in counter visitors.

Public waiting room lobby displays show only token numbers and pseudonymous indicators, never displaying patient full names, mobile numbers, or clinical reasons for visit.

04Doctor KYC Verification & Document Auto-Purge

Every doctor is verified against official Medical Council registries prior to accepting appointments.

In accordance with UIDAI regulations, doctor Aadhaar identity uploads are automatically and permanently purged within 30 days of verification.

05Vulnerability Disclosure & Security Reporting

We maintain a dedicated vulnerability disclosure program. If you believe you have discovered a security or privacy vulnerability in any Soefer application or service, report it immediately to security@soefer.com.

Please include reproduction steps and a technical description without accessing, altering, or extracting user data. We acknowledge valid reports within 24 hours.

End of documentBack to top ↑
On this page
Infrastructure & Data EncryptionStaff & Front-Desk Access BoundariesQueue Integrity & Public Display PrivacyDoctor KYC Verification & Document Auto-PurgeVulnerability Disclosure & Security Reporting
© 2026 Soefer™
Terms of ServicePrivacy PolicyCancellation & RefundSecurityMedical DisclaimerContact Us
Made for better days.