Authenticated, scoped workspaces
Signed session cookies protect workspace routes. API requests resolve a tenant and module access is checked against the signed-in role or explicit custom permissions.
This page separates controls implemented in the CareFlow application from deployment responsibilities and certifications CareFlow does not currently claim. It is a product transparency record, not a substitute for a customer-specific security review.
Configuration can still affect a production deployment, so customer due diligence remains important.
Signed session cookies protect workspace routes. API requests resolve a tenant and module access is checked against the signed-in role or explicit custom permissions.
Owners and managers can assign roles, narrow a staff member to selected modules and immediately deactivate an account.
Only the workspace owner can export tenant-scoped operational records, after re-entering the current password. The event is logged; password hashes and authentication tokens are excluded.
Only the workspace owner can schedule deletion after password and exact-name confirmation. A seven-day grace period allows recovery; operational records are then erased while a pseudonymised, redacted audit minimum is retained for up to 365 days.
Sensitive actions create tenant-scoped audit records with actor, role, action, target and time. CareFlow does not describe this application-level trail as an external certification.
CareFlow verifies Checkout and raw webhook signatures, then fetches Razorpay's payment record and confirms captured status, order, amount and INR currency before activation. Duplicate callbacks are idempotent and pending orders are reconciled server-side.
The final assurance level depends on three layers working together.
Tenant and module scoping, role controls, application audit records, export and deletion flows, payment verification and human approval boundaries.
Database and object-storage region, encryption and backup settings, secret management, monitoring, incident response, retention and recovery testing.
Authorised users, lawful data collection, least-privilege role assignment, device security, clinical governance and review of AI-assisted output.
New workspaces start empty. Teams enter or import real master and operational data after access is configured.
Application requests scope records to the resolved tenant and authorised modules.
The owner re-enters the current password before downloading operational, configuration, billing and audit records in structured JSON.
The owner confirms password and workspace name, receives seven days to cancel, and then operational records are erased. A redacted security and financial audit minimum expires after its separate retention window.
CareFlow does not present the following as current certifications or universal guarantees:
A customer requiring one of these frameworks should request a scoped readiness and contractual review before placing regulated data in production.
These links explain the external frameworks. They do not certify CareFlow.
Send the intended deployment, data categories, required framework and contractual controls. We will answer against evidence rather than badges.
Start a trust review