
Security Policy
AFG. Futech is committed to protecting the confidentiality, integrity, and availability of Shafa’s data and systems.
- Data Security Measures
We implement industry-standard practices, including:
Encryption
- All data transferred online uses HTTPS / TLS encryption.
- Sensitive data is encrypted at rest on our servers.
Password Security
- Passwords are hashed using secure algorithms.
- No passwords are stored in plain text.
- Account lockouts for repeated failed logins.
Role-Based Access
Different users (doctor, nurse, admin, accountant) have different access levels.
Regular Backups
- Encrypted backups
- Multiple locations
- Disaster recovery plans
- Server & Infrastructure Security
- Firewalls
- Intrusion detection systems
- Access logging and IP monitoring
- Limited access for server engineers
- Cloudflare protection for online services
- Application-Level Security
- Input validation
- Anti–SQL injection
- Anti–XSS filters
- Session security with tokens
- Two-factor authentication (if enabled by the user)
- User Responsibilities
To protect your data, you must:
- Use strong passwords
- Keep login information private
- Update software regularly
- Restrict access inside your clinic
- Reporting a Security Issue
If you suspect a security breach or vulnerability, please contact:
[email protected]
We respond within 24 hours.