Security

Security architecture

Hospitales.net connects organizations that carry regulatory, commercial and patient-adjacent responsibility. Security is treated as infrastructure, not a feature — described here at a business level for executives evaluating the platform.

Verified identity
Every organization is verified before it can be discovered by others — no anonymous or self-declared identity grants network visibility.
Multi-factor authentication
Administrative and sensitive actions require a second authentication factor beyond a password, enforced at the session level.
Least-privilege access
Access to organizational data and administrative functions is scoped precisely to role and organization, matched to what the task requires.
Full auditability
Every meaningful action — approvals, capability changes, data access — is recorded in an immutable audit trail.

Data isolation between organizations

Row-level security enforced at the database layer keeps each organization’s private data, documents and commercial information exclusively accessible to that organization, independent of any application-level bug.

Regulatory-grade capability verification

Capabilities that grant access to sensitive workflows require evidence review by an independent reviewer, always someone other than the person who submitted the capability claim.

Session and credential handling

Authentication sessions expire, tokens stay scoped to what client-side code strictly requires, and administrative operations require an elevated, time-bound authentication level.

Responsible disclosure

Security researchers and partners who identify a vulnerability can report it through the contact channel in the site footer; we commit to acknowledging reports and addressing verified issues.

This page describes security principles at a business level for evaluation purposes. It is not a substitute for a technical security assessment or a signed data processing agreement, both available on request once an organization moves past early access.