Skip to content
TidySession
Security and access

Clear boundaries around your workspace.

Security is part of the product’s everyday behaviour. Here is what the current release does, and what remains to be verified before clinical use.

Access follows the person’s role

AccountAccess
Practice ownerThe practice’s records, team, settings, invitations and activity history.
PractitionerAssigned patient records and shared practice templates.
Patient portalThe linked person’s appointments, questionnaires, reflections and shared files.

Permission checks take place on the server. A record or file identifier alone does not grant access. Suspending a practitioner or revoking a portal connection takes effect on later requests.

Safeguards in the application

  • Clinical writes recheck account access and record assignment as the change is saved.
  • Record versions prevent an older draft from silently overwriting newer edits.
  • Appointment booking checks for overlapping sessions and current practitioner assignment.
  • Invitation secrets are stored as hashes, are tied to an email address and can be revoked.
  • Downloads check access again and are served with private, no-store headers.
  • The installable web app does not cache clinical records for offline access.
  • Activity history records actions without copying note contents or questionnaire responses into the log.

Payment and provider boundaries

Subscription access is based on verified server-side billing events. A checkout return page cannot grant paid access. Stripe keys and AI credentials belong in server configuration and are never sent to the browser.

Optional recording and AI assistance have separate controls. Every transcript and draft should be checked against the practitioner’s own knowledge before becoming part of a clinical record.

Evaluation status

The current release has automated checks for access boundaries, invitation races, record revisions, subscription entitlement and file access. These checks support development; they do not establish regulatory compliance or replace an independent security assessment.

Clinical rollout still requires review of the hosting and processor arrangements, retention and deletion, incident response, backup restoration, multi-account sign-in and target devices. TidySession does not claim GDPR or HIPAA certification.

Read the current privacy and data-use information.