Data protection that starts at the database engine.
EnaBed is engineered for regulated healthcare. Every security and compliance property is a structural design decision — not a post-launch configuration.
Security Pillars
Six layers of protection.
PostgreSQL RLS
Row-Level Security policies enforced at the database engine. Every query scoped to the current tenant UUID via session variable. Cross-tenant leakage is structurally impossible.
OIDC via EnaCore Identity
Admin authentication through an enterprise OIDC provider with PKCE. No passwords in EnaBed. Short-lived access tokens with Redis session store.
HMAC-SHA256 Audit
Immutable, append-only audit log with cryptographic hash chaining. Retained 3–7 years by plan tier. Chain verified on demand.
Encrypted Secrets
Webhook signing secrets, SMS provider credentials, and session data encrypted with AES-GCM before storage. Keys managed via environment, never in source code.
KVKK & GDPR Consent
Configurable consent where patient identifiers are captured. Explicit consent recorded at submission. Configurable data retention periods.
Per-tenant Object Storage
Exported reports and attachments stored in per-organization Huawei OBS buckets with encryption at rest.
Security FAQ
See EnaBed in your facility.
Contact us — we'll walk through facility modeling, bed workflows, live updates, and your enterprise configuration together.