Security

A private-practice record, looked after

Client data is hosted in the EU. The design is POPIA and GDPR-minded. This page also says which compliance claims we do not make.

Safeguards we describe today

  • Client data is hosted in the EU.
  • A POPIA and GDPR-minded design. Compliance is not claimed, and no certification is claimed.
  • Role-based access, so people see only what their role allows.
  • Signed, audit-friendly records.
  • You stay in control of Within Assist. A suggestion is not saved until you apply it.

Microsoft sign-in is coming soon

Secure sign-in with Microsoft, including a second factor, is coming soon. It is not available yet. Today the safeguards above are what this page describes.

Where client data is hosted

Client data for the products is hosted in the EU.

POPIA

The design is POPIA-minded for practices in South Africa. This page does not say that Reach Within is POPIA compliant, and it does not claim a certification.

GDPR

The design is GDPR-minded for clinicians in the United Kingdom. This page does not say that Reach Within is GDPR compliant, and it does not claim a certification.

What we do not claim

We do not claim POPIA compliance, GDPR compliance, or HIPAA compliance. We do not claim a certified hospital EMR or an NHS system. Privacy and terms for this marketing website are still drafts.

Questions about security for your practice?

Use the contact form. Please do not send client records or clinical notes through it.