Security & Trust

Security & Trust

How ClinPlacer protects institutional and student data — infrastructure, encryption, access control, and how to report a vulnerability.

Encrypted by Default Role-Based Access Responsible Disclosure Welcome
Last updated: July 2026
Overview

Built to hold up under inspection

Placement records carry sensitive academic and personal information. Here's a straightforward account of what protects it, and what to do if you find a problem.

Kenya Data Protection Act aligned Encrypted in transit & at rest Role-based access controls

Our Approach

ClinPlacer handles placement records, capacity data, and personal information belonging to Schools, Facilities, and Students. Security isn't a feature we added afterward — it shapes how the Platform is built, hosted, and operated.

This page describes the safeguards currently in place. For how we collect and use personal data, see our Privacy Policy. For platform conduct standards, see our Acceptable Use Policy.

Infrastructure & Hosting

The Platform runs on access-controlled cloud infrastructure with the following practices:

  • Production systems are separated from development and testing environments
  • Infrastructure access is restricted to authorized engineering staff on a need-to-know basis
  • Systems are kept current with security patches and updates

Data Encryption

Data is encrypted both while it moves and while it's stored:

  • In transit — all traffic between your browser or app and ClinPlacer is encrypted using HTTPS/TLS
  • At rest — stored data, including placement and student records, is encrypted on disk

Access Control & Authentication

Access to institutional data is governed by role-based permissions, so each User sees only what their role requires:

  • Separate permission levels for Administrators, supervisors, and Students
  • Two-factor authentication available for accounts that support it
  • Session timeouts and credential requirements designed to reduce the risk of unauthorized access

Account holders are responsible for keeping their own credentials confidential — see our Acceptable Use Policy for the security responsibilities every User agrees to.

Monitoring & Incident Response

We monitor the Platform for signs of suspicious activity and maintain a process for responding to security incidents:

  • Automated monitoring for unusual access patterns and system anomalies
  • A defined internal process for triaging, containing, and resolving security incidents
  • Affected Institutions are notified without undue delay if an incident affects their data, in line with our obligations under Kenyan law

Backups & Disaster Recovery

Platform data is backed up on a regular schedule, with backups stored separately from production systems. We maintain a disaster recovery process intended to restore service and data in the event of a major failure.

These measures reduce, but cannot fully eliminate, the risk of downtime or data loss — see our Terms of Service, Section 15 (Service Availability), for how this is addressed contractually.

Reporting a Vulnerability

If you believe you've found a security vulnerability in ClinPlacer, we want to hear about it before anyone else does.

  • Email legal@clinplacer.com with a description of the issue and steps to reproduce it
  • Give us a reasonable opportunity to investigate and address the issue before disclosing it publicly
  • Do not access, modify, or delete data beyond what is needed to demonstrate the vulnerability

Good-faith research

We will not pursue legal action against anyone who reports a vulnerability responsibly, in good faith, and in line with the guidance above.

Shared Responsibility

Security is a shared effort between ClinPlacer and the Institutions and Users on the Platform:

  • ClinPlacer secures the Platform's infrastructure, code, encryption, and access controls
  • Institutions and Users are responsible for protecting their own credentials, devices, and the accuracy of who they grant access to

Compliance & Data Protection

Our handling of personal data is aligned with the principles of the Kenya Data Protection Act, 2019 — lawfulness, purpose limitation, data minimization, and accountability. See our Privacy Policy and Compliance page for details.

These pages describe our current practices. ClinPlacer does not claim formal certifications such as ISO 27001, SOC 2, or HIPAA unless separately confirmed in writing.

Changes to This Page

We update this page as our security practices evolve. Material changes will be reflected here with an updated "Last updated" date.

Contact Us

For security questions, vulnerability reports, or documentation requests from your procurement or IT team, reach out through the following channels:

Security & Legal

legal@clinplacer.com

General Support

info@clinplacer.com

Business Contact

+254 118 193 750

Visit our Contact Form

Questions from your IT or procurement team?

We're glad to walk through our security practices in more detail, or provide documentation to support your institution's own review process.