Data Security
Last Updated: August 27, 2026
Data Security at ClinVio™
This page describes the access controls and data-protection practices ClinVio implements. ClinVio describes only controls that are in place and does not claim certifications it has not obtained.
Last Updated: August 27, 2026
Operator: TBrij LLC d/b/a ClinVio — ClinVio is operated by TBrij LLC, a Texas limited liability company.
Access Control
- Authenticated access — users must authenticate to access ClinVio.
- Role-based permissions — doctors, company users, and administrators see only the functionality and data appropriate to their role.
- Company isolation — a company can access only its own studies, contracts, and related records.
- Doctor isolation — a doctor can access only their own profile, engagements, and records.
- Administrative permissions — administrative actions are limited to authorized administrators and are recorded.
Data Protection
Controls ClinVio implements include:
- Secure transport for data in transit.
- Protected storage for data at rest.
- Controlled document access for sensitive uploads.
- Short-lived, signed URLs for private document access.
- Secure authentication and session handling.
- Audit logging of significant actions.
Sensitive Documents
Credentials, identity documents, contracts, and financial information are subject to restricted access. Identity documents have restricted access and are not shared with companies or recruiters.
Company Access
Company users do not receive unrestricted access to the ClinVio doctor database. ClinVio shares approved professional profiles with companies only for specific, approved requirements.
Doctor Data Sharing
Doctor profile sharing with companies is controlled through ClinVio's sharing workflows. A doctor's information is shared only when approved for a specific requirement, and only the approved subset of professional information is included.
Monitoring & Audit
ClinVio maintains an audit trail of significant administrative and data-access actions at a high level to support accountability and investigation.
Incident Reporting
Report a Security Concern: if you believe you have identified a security issue, please submit a Privacy Request and select "Security concern." Include a description without sensitive details. ClinVio will review the report.
Responsible Disclosure
ClinVio appreciates responsible disclosure of suspected security vulnerabilities. If you believe you have found a vulnerability, report it through the Privacy Request page with "Security concern" selected. Please do not attempt to exploit, test, or access data beyond what is necessary to identify the issue.
No Unsupported Claims
ClinVio does not claim HIPAA compliance, SOC 2 certification, FDA approval, or any other certification it has not obtained. Compliance references describe design objectives or planned assessments, not completed certifications.