Schema-level tenant isolation
Each pharmacy's tenant-owned records live in a separate PostgreSQL schema. Tenant routing is selected from the pharmacy hostname before tenant data is queried.
Security architecture
DosePoint protects pharmacy and patient data through layered technical and organizational controls. Security controls support responsible use; they do not make every pharmacy deployment automatically compliant with every country's law.
Each pharmacy's tenant-owned records live in a separate PostgreSQL schema. Tenant routing is selected from the pharmacy hostname before tenant data is queried.
Authenticated pharmacy users receive role-based access. The product separates Admin, Pharmacist, Receptionist, and Nurse responsibilities rather than treating every staff account alike.
Patient-record access and financial mutations are audit-logged so sensitive actions can be traced without logging raw medical record content or credentials.
The platform uses encrypted transport, encrypted AWS storage, and automated database backups as layers in its data-protection approach.
Production infrastructure is hosted in AWS eu-central-1 (Frankfurt). This is an infrastructure fact, not a promise of local data residency in another country.
Patient mobile identity is per pharmacy. A patient account is not a cross-pharmacy identity, balance, or shared medical record.
Country requirements
Healthcare, privacy, retention, cross-border transfer, patient-rights, and breach-notification requirements differ by country. Pharmacies remain responsible for their legal obligations and should obtain local advice. Contact Teliyadu to assess product configuration, contracting, and data-processing requirements for your market.
Responsible disclosure
Email support@dosepoint.co with the subject “Security Vulnerability.” Include the affected surface, reproducible steps, and potential impact. Do not include real patient data, passwords, tokens, or other secrets in the report.
Need a market-specific data-protection discussion?