Security
How Tokenn protects clinic and patient data at every layer of the stack.
Last updated 19 May 2026
Found a vulnerability? Message us on WhatsApp +91 63851 72443. We respond within 24 hours and offer responsible disclosure credit.
Infrastructure
Hosting
Tokenn runs on a dedicated server in an ISO 27001 certified data centre operated by Hetzner Online GmbH in Helsinki, Finland (EU). Patient and clinic data is stored there, encrypted at rest.
Network
- All traffic encrypted with TLS 1.2 minimum (TLS 1.3 preferred).
- HTTP Strict Transport Security (HSTS) enforced.
- Database network access is IP-restricted to our application servers only.
- Cache / queue store accessed over TLS with token authentication.
Application security
Authentication
| Control | Detail |
|---|---|
| Password storage | Strong one-way hashing: MPINs are never stored in plain text |
| Session tokens | Short-lived signed session tokens, kept in memory (not localStorage) |
| Role enforcement | Server-side on every request: owner, doctor, receptionist scopes |
| Rate limiting | 100 requests / minute per IP on all /api routes |
Data protection
| Data | Protection |
|---|---|
| WhatsApp access tokens | AES-256 encrypted at rest; decrypted only in memory when sending messages |
| MPINs / passwords | One-way hashed: not reversible |
| Patient phone numbers | AES-256 encrypted at rest (including visit reasons and booking answers); looked up via a keyed index, never the plaintext. Never shared across clinics |
| Database at rest | Provider-side encryption at rest (AES-256) by default |
API security
- CORS: responses restricted to your configured frontend origin only.
- Security headers: Content-Security-Policy, X-Frame-Options, and Referrer-Policy set on every response.
- Webhook verification: incoming WhatsApp webhooks are cryptographically signature-verified before processing.
- Input validation: all API inputs validated and size-limited.
- Clinic isolation, every query scoped to the requesting clinic's ID; cross-clinic data access is not possible.
- IDOR protection: token mutations (mark done, skip) verified against clinic ownership before applying.
What Tokenn does not store
The narrowest control is the one that removes whole categories of risk: Tokenn has no facility for uploading or storing clinical data. There is no file upload anywhere in the product, and no field for a lab result, scan image, clinical photo, prescription or treatment note. A breach of Tokenn cannot expose medical records, because Tokenn never holds them.
The health-adjacent fields it does hold are short and typed or spoken by the patient or the receptionist: the visit reason ("fever", "follow-up") and, where a department asks them, the answers to its booking questions ("Any allergies?"). They are used to route the patient and prepare the doctor, and are encrypted at rest alongside the phone number and is covered in the Privacy Policy and DPA.
Third-party integrations
We integrate a small set of providers to deliver the service. A current, named list with locations is available to clinics on request.
| Service | Access scope | Credential handling |
|---|---|---|
| WhatsApp messaging | Send messages on behalf of the clinic's WhatsApp account only | Access token AES-256 encrypted per clinic |
| AI replies (USA) | Generates AI replies. The patient's own message, which may contain personal data they choose to share, plus queue/clinic context is sent; stored identifiers (name/phone) are not. | Server-side API key only; never exposed to client |
| Payment processing | Booking credit purchases | Webhook signatures cryptographically verified; card data never touches Tokenn servers |
| Managed database | Primary data store | Credentials stored as server env vars; rotated on request |
Operational security
- Environment variables never committed to source control.
- Encryption keys and JWT secrets generated with
openssl rand -hex 32(256-bit entropy). - Dependencies audited with
npm auditon every deployment. - Server logs retained for 30 days. Phone numbers are masked and we avoid logging patient names or message content.
- Database backups taken daily with 7-day retention.
Incident response
In the event of a confirmed data breach affecting clinic or patient data:
- Affected clinics notified within 72 hours of discovery.
- Incident report provided within 7 days describing scope, cause, and remediation.
- Where required by DPDP Act 2023, the Data Protection Board notified within prescribed timelines.
Responsible disclosure
We welcome security researchers. If you discover a vulnerability:
- Message us on WhatsApp +91 63851 72443 with steps to reproduce.
- Do not access, modify, or delete production data.
- Give us 90 days to fix before public disclosure.
We will acknowledge receipt within 24 hours and provide a fix timeline within 5 business days. Researchers who follow this policy will be credited publicly if they wish.
Operated by Cyberzio Innovations Pvt Ltd for TOKENN: WhatsApp queue and token management for clinics in India. See also Privacy Policy, Terms of Service, Security and Data Processing Agreement.