Security

Last Updated: 2026-09-08

Security at ClinVio™

This page describes the security controls ClinVio implements. We describe only controls that are in place and do not claim certifications we have not obtained.

Operator: TBrij LLC d/b/a ClinVio — ClinVio is operated by TBrij LLC, a Texas limited liability company.

Last Updated: 2026-09-08 · Version: 1.0


Authentication

  • Authenticated access — users must authenticate to access ClinVio.
  • Secure session handling — authentication tokens are managed server-side and are not exposed to client-side storage beyond what is necessary for the session.
  • Role-based access — doctors, company users, and administrators see only the functionality and data appropriate to their role.

Role-Based Access Control

  • Doctor — access is limited to the doctor's own profile, engagements, documents, and records.
  • Company — access is limited to the company's own organization, studies, contracts, and explicitly shared physician profiles.
  • ClinVio Admin — access to administrative information necessary for platform operations.
  • Verification Reviewer — access to verification information necessary for the reviewer's role.
  • Finance — access to financial information necessary for the role.

Authorization is enforced server-side. Route hiding is not the sole access control mechanism.


Company Data Isolation

A company can access only its own studies, contracts, engagements, and related records. One company cannot access another company's information. Company users do not receive unrestricted access to the ClinVio physician database.


Controlled Physician Profile Sharing

Doctor profile sharing with companies is controlled through ClinVio's sharing workflows. A doctor's information is shared only when approved for a specific requirement, and only the approved subset of professional information is included. Companies cannot browse unshared doctors.


Secure Transport

ClinVio uses encrypted transport (TLS/HTTPS) for data in transit between clients and the platform.


Document Protection

Credentials, identity documents, contracts, and financial documents are subject to restricted access. Private document access uses short-lived, signed URLs. Expired or revoked access is enforced where supported. Access events are logged where appropriate.

Identity documents and raw verification documents are not shared with companies unless explicitly authorized.


Audit Logging

ClinVio maintains an audit trail of significant administrative and data-access actions to support accountability and investigation. Audit logs are retained according to security policy.


Security Monitoring

ClinVio monitors platform activity for signs of unauthorized access or misuse. Significant security events are reviewed and may be escalated for investigation.


Vendor Management

ClinVio maintains an internal subprocessor register of third-party vendors that process ClinVio information. Each vendor is evaluated for data access, security review status, agreement status, and transfer mechanism. Vendors are not assumed acceptable solely because they are well-known providers.


Incident Response

ClinVio maintains an internal incident response process. Security incidents are recorded, assessed for severity, and flagged for legal/privacy review where appropriate. Regulator and user notifications are not automatically triggered by software logic — they require human assessment.


Vulnerability Reporting

Report a Security Concern: if you believe you have identified a security issue, please submit a Privacy Request and select "Security concern." Include a description without sensitive details. ClinVio will review the report.

We appreciate responsible disclosure of suspected security vulnerabilities. Please do not attempt to exploit, test, or access data beyond what is necessary to identify the issue.


Sensitive Data Handling

ClinVio does not intentionally log passwords, authentication tokens, OAuth secrets, full government identifiers, bank details, tax identifiers, or complete credential documents. Sensitive identifiers are masked in logs and analytics where avoidable.


No Unsupported Claims

ClinVio does not claim to be "100% secure." ClinVio does not claim HIPAA compliance, SOC 2 certification, FDA approval, or any other certification it has not obtained. Security references describe controls and planned assessments, not completed certifications.