psisula
Security

How client data is protected

How the data is stored and who can reach it, in plain language. If you have found a security vulnerability, reach us at the bottom of this page.

What we publish

The texts below are published on this site in both Turkish and English; there is no gated report to download — they can be read directly.


The safeguards around your data

What runs in the product today, without the implementation detail.

Access by role

Owner, admin, therapist, front desk and supervisor each work at their own permission level. Front desk cannot see clinical notes; a supervisor reads notes read-only.

Encrypted in storage and in transit

Clinical notes, treatment plans, diagnoses and assessment answers are stored encrypted, and all traffic between your browser and the server is protected with TLS.

Clinics stay separate

A clinic only ever sees its own records. In the client portal, every access is separately checked against whether the record really belongs to that client.

No client data in logs

System logs carry no client names, phone numbers, note text, assessment answers or portal messages.

Change history

Create, edit and delete actions are written to the audit log, and every piece of AI-generated content is recorded as well.


Vulnerability disclosure

If you believe you have found a security vulnerability in the product, write to us. We don't have a bounty programme yet, but thank you in advance for acting responsibly.

How to report

[email protected]
  • We reply to your report within three business days.
  • We keep you informed while it is assessed and fixed.
  • Good-faith research conducted under these rules is not treated as a hostile act.

Before you report

  • Do not modify, copy or retain any data you reach — stop the moment you see it.
  • Do not run load tests that would slow down or interrupt the service.
  • Send us the finding with reproduction steps before disclosing it publicly.

Out of scope

Social engineering, phishing and physical attacks
Denial-of-service (DoS/DDoS) attempts, and SMS or email bombing
Missing headers or best-practice advice with no demonstrated impact
Automated scanner output without a working proof of concept
Vulnerabilities in third-party services such as Zoom, Google Meet or the SMS provider

Let's set up a short call

In about fifteen minutes we'll walk you through the product on a demo built around your practice, and answer whatever is on your mind.

30-day money-back guarantee.