Security
Last updated 29 September 2026
The architectural safeguards, cryptographic protocols, and operational procedures protecting user identity, queue integrity, and clinic workflows on Soefer.
On this page
01Infrastructure & Data Encryption
In-Transit Protection: All network communications between mobile apps, clinic interfaces, and backend servers are strictly encrypted using Transport Layer Security (TLS 1.3) with perfect forward secrecy.
At-Rest Protection: Operational databases, appointment queues, and transaction ledgers are encrypted at rest using AES-256 transparent data encryption.
Domestic Data Residency: Central databases and synchronization services are hosted exclusively in secure domestic data centres located within India in compliance with the Digital Personal Data Protection Act (DPDP Act, 2023).
02Staff & Front-Desk Access Boundaries
Clinic front-desk personnel and receptionists operate under restricted Kiosk Mode permissions. Front-desk staff can verify tokens and announce turns, but are strictly prohibited from viewing doctor financial earnings, consultation notes, or account credentials.
The platform enforces strict privacy boundaries: clinic counter devices only receive the minimum pseudonymous queue details necessary for check-in, without storing patient phone numbers, dates of birth, or personal profile identifiers.
03Queue Integrity & Public Display Privacy
Our sequential token allocation engine guarantees queue integrity and eliminates duplicate token bookings between online patients and walk-in counter visitors.
Public waiting room lobby displays show only token numbers and pseudonymous indicators, never displaying patient full names, mobile numbers, or clinical reasons for visit.
04Doctor KYC Verification & Document Auto-Purge
Every doctor is verified against official Medical Council registries prior to accepting appointments.
In accordance with UIDAI regulations, doctor Aadhaar identity uploads are automatically and permanently purged within 30 days of verification.
05Vulnerability Disclosure & Security Reporting
We maintain a dedicated vulnerability disclosure program. If you believe you have discovered a security or privacy vulnerability in any Soefer application or service, report it immediately to security@soefer.com.
Please include reproduction steps and a technical description without accessing, altering, or extracting user data. We acknowledge valid reports within 24 hours.