Security
Security at DoctorIn
DoctorIn keeps the attack surface small by design. The reception panel is protected by a PIN, clinic pages are served over HTTPS, patients see token numbers instead of names, and DoctorIn stores no medical records because it is not an EMR. This website has no forms and loads no third-party scripts beyond cookie-free analytics.
Last updated: Written by Surya Raj Salve
How is the reception panel protected?
Only someone with the clinic's PIN can open the reception panel at /admin and change the token or the doctor's status. Patients see a read-only page.
Are clinic pages encrypted?
Yes. Free hosting and SSL are included with every plan, so every clinic page is served over HTTPS.
What patient information is visible on a clinic page?
None. The token board shows token numbers only. Doctor status is one of three labels. Booking details are not shown on the page; they travel as a WhatsApp message from the patient's phone to the clinic.
Does DoctorIn store medical records?
No. DoctorIn is not an EMR or HMIS. It holds no patient records, prescriptions or billing data.
How is this website secured?
- A Content Security Policy that blocks scripts, styles, fonts and connections from other sites.
- Framing blocked (X-Frame-Options and frame-ancestors), so the site cannot be embedded by others.
- X-Content-Type-Options, a strict Referrer-Policy and a Permissions-Policy that turns off camera, microphone and location access.
- No forms, no logins and no third-party scripts except cookie-free analytics.
How do I report a security issue?
Message or call +91 93463 16627 and describe what you found. Please do not test against live clinic pages without permission.