Skip to content

Security and access

Everyone can use the system; not everyone can see everything.

Stokontrol supports controlled clinical work through role-based access, tenant isolation and traceable activity.

Security and access

Clinic-scoped access

Access is limited to the relevant clinic and authorised user.

Security and access

Secret protection

Private service credentials are never returned to the browser.

Security and access

Traceable history

Where appropriate, activity history is retained instead of silently deleting evidence.

Security and access

Secure sign-in and redirects

Once two-step verification is enabled, the workspace stays closed until the authenticator code is complete; post-login redirects remain limited to trusted application paths.

Security and access

Auditable actions

Critical operations are recorded in a reviewable form.

Security and access

Minimum disclosure

Platform administration does not expose patient clinical detail in its product surface.

Clear disclosure

A security approach is not a legal-compliance guarantee.

This page explains the technical approach. Regulatory compliance must also be assessed against each clinic's processes and applicable law.

Can one clinic see another clinic's data?

No. Clinic context and server-side authorisation are checked for each protected access.

Can permissions be changed?

An authorised clinic administrator may adjust permissions; critical actions remain protected on the server.

Are patient files public?

No. Clinical files use authorised access and private storage rules.

Safe start

Try the product before setting up your clinic.

The public demo is isolated from real clinic data. Account setup is a separate controlled flow.