How ClinPlacer protects institutional and student data — infrastructure, encryption, access control, and how to report a vulnerability.
Placement records carry sensitive academic and personal information. Here's a straightforward account of what protects it, and what to do if you find a problem.
ClinPlacer handles placement records, capacity data, and personal information belonging to Schools, Facilities, and Students. Security isn't a feature we added afterward — it shapes how the Platform is built, hosted, and operated.
This page describes the safeguards currently in place. For how we collect and use personal data, see our Privacy Policy. For platform conduct standards, see our Acceptable Use Policy.
The Platform runs on access-controlled cloud infrastructure with the following practices:
Data is encrypted both while it moves and while it's stored:
Access to institutional data is governed by role-based permissions, so each User sees only what their role requires:
Account holders are responsible for keeping their own credentials confidential — see our Acceptable Use Policy for the security responsibilities every User agrees to.
We monitor the Platform for signs of suspicious activity and maintain a process for responding to security incidents:
Platform data is backed up on a regular schedule, with backups stored separately from production systems. We maintain a disaster recovery process intended to restore service and data in the event of a major failure.
These measures reduce, but cannot fully eliminate, the risk of downtime or data loss — see our Terms of Service, Section 15 (Service Availability), for how this is addressed contractually.
If you believe you've found a security vulnerability in ClinPlacer, we want to hear about it before anyone else does.
Good-faith research
We will not pursue legal action against anyone who reports a vulnerability responsibly, in good faith, and in line with the guidance above.
Our handling of personal data is aligned with the principles of the Kenya Data Protection Act, 2019 — lawfulness, purpose limitation, data minimization, and accountability. See our Privacy Policy and Compliance page for details.
These pages describe our current practices. ClinPlacer does not claim formal certifications such as ISO 27001, SOC 2, or HIPAA unless separately confirmed in writing.
We update this page as our security practices evolve. Material changes will be reflected here with an updated "Last updated" date.
For security questions, vulnerability reports, or documentation requests from your procurement or IT team, reach out through the following channels:
Security & Legal
legal@clinplacer.comGeneral Support
info@clinplacer.comBusiness Contact
+254 118 193 750We're glad to walk through our security practices in more detail, or provide documentation to support your institution's own review process.