Security
Your practice data is yours. We keep it that way.
When you store client notes, bookings and payment details in ClientWell, you are trusting us with the heart of your practice. Here is how we protect that data, where it lives, and who can access it.
Hosted in the cloud, managed by us
ClientWell runs on managed edge infrastructure with a separate managed Postgres database. We do not host the platform on a server under someone's desk — it is built for production workloads from day one.
Encrypted in transit and at rest
All traffic between your browser and ClientWell is protected by HTTPS/TLS. Data at rest is encrypted by our infrastructure providers, and authentication tokens are handled through an industry-standard identity service.
Automated backups
Your workspace data is backed up automatically by our database provider. If something goes wrong, we can restore from a recent backup rather than asking you to start again.
Workspace isolation
Every workspace is separated at the database layer using row-level security. One practice cannot read another practice's clients, sessions, notes or documents — even if someone tried to query for them directly.
Role-based access
Invite team members with scoped roles. Owners and admins can manage billing and workspace settings; members get access to the day-to-day tools they need. You control who sees what.
Sage does not train on your data
Our AI assistant, Sage, helps draft messages and answer questions. It does not send messages or take payments on its own, and we do not use your client records or Sage chats to train third-party AI models.
What we mean by "secure enough for a health practice"
We know "secure" can sound like marketing fluff. For a solo practitioner or small clinic, it really means three things: your data is not easy to steal, it is not easy to lose, and only the right people can see it. The controls above are how we deliver on each of those.
A shared responsibility
We look after the platform, the infrastructure and the security controls built into it. You look after your own account: use a strong password, only invite people you trust, and think carefully about what client information you collect and why. If you are unsure about your obligations under New Zealand privacy law, we recommend speaking with your professional body or a privacy advisor.
Compliance and certifications
This page describes the security practices we have in place today. It is not a SOC 2, HIPAA, ISO 27001 or GDPR certification. If your insurer, professional association or a corporate client needs specific security wording, email us and we will provide our shared-responsibility security policy and HISF checklist mapping.
Report a security issue
If you believe you have found a vulnerability or a data-handling problem, please email security@myclientwell.com. Do not post details publicly before we have had a chance to respond. We will acknowledge your report and keep you updated as we investigate.
