🔒 Enterprise-grade security

Your patients' data, protected the right way

Clarus is built on a "security-first" principle: complete isolation, strong encryption, and tamper-proof auditing — aligned with regional data-protection regulations.

🗄️

A separate database per client

True data isolation at the database level — no mixing, no leakage between labs.

🔐

AES-256-GCM encryption

Sensitive fields encrypted at rest, with protected master keys.

🔑

Password hashing

pbkdf2-sha256 with high iteration counts — passwords are never stored in plaintext.

📜

Chained audit log

An immutable hash chain that records who did what and when — inspection-ready.

👥

Fine-grained permissions (RBAC)

Precisely defined roles for every user, following the principle of least privilege.

💾

Encrypted backups

Periodic encrypted backups with restore verification — your data is never lost.

🛡️

Session protection

Expiring session tokens, with lockout after failed attempts.

🌐

Interoperability standards

HL7 v2 · ASTM · FHIR R4 · LOINC — for secure, unified integration.

📍

Data residency

Regional hosting options to meet data-sovereignty requirements.

Isolation architecture

A database per lab — no exceptions

Unlike systems that mix everyone's data into a single table, Clarus gives each lab a fully independent database. That means true security isolation, consistent performance, and independent backup and restore for every client.

  • ✅ No cross-client leakage risk
  • ✅ Restore a single client without affecting others
  • ✅ Clean horizontal scalability
🏥 Nile LabIsolated DB
🏥 Gulf LaboratoriesIsolated DB
🏥 Atlas LabIsolated DB
Each database is encrypted and backed up separately
Security & compliance

Trusted with patient data

Defense in depth — and your data stays yours.

🔐

AES-256 & TLS 1.3

Encrypted at rest and in transit, end to end.

🧾

Immutable audit trail

Every action recorded and tamper-evident.

🏢

Per-tenant isolation

Each lab's data isolated; optional dedicated database or server.

ISO 15189 & CAP-ready

Evidence — QC, EQA, CAPA, chain of custody — ready for audits.

🌍

GDPR · ZATCA / ETA

Privacy and regional tax compliance built in.

📤

Data ownership & export

Your data is yours — export it at any time.

Security is not an add-on

It is the foundation of every Clarus instance — even the free trial.

Start securely ←