Security at Historia
We protect clinical information with technical and access controls that reflect the product as it exists today.
Infrastructure and location
Historia uses Cloudflare services. We do not currently promise country-exclusive data residency; regional pinning is planned for a later stage.
Encryption
Cloudflare provides encryption in transit and at rest for the infrastructure services Historia uses.
Workspace-scoped access
Access is scoped by Workspace and member type. Clinicians can access shared clinical content in their Workspace; reception staff work with the Schedule and demographics, without authorship or access to clinical content.
Authentication
Historia supports email and password sign-in with email verification, Google sign-in, and two-factor authentication. The service manages active sessions and invalidates them when appropriate, such as when a member is removed from a Workspace.
Records and auditability
Each clinical record retains the identity of the Clinician who authored and Finalized it, preserving clinical authorship. AI only prepares a Draft; a Clinician must review, edit, and Finalize it in accordance with the regulations of their country.
Backup and recovery
The database supports point-in-time recovery through Cloudflare D1 Time Travel. A bookmark is recorded before each deployment to support operational recovery if needed.
Vulnerability reporting
If you identify a potential vulnerability, report it responsibly to security@historiamd.com and include enough information to reproduce it. The Historia team will review the report and coordinate with you if more information is needed.
Country-specific provisions
Each Workspace is created with a country, which determines the legal framework for its clinical records. In Chile, clinical-record authorship and finalization are governed by Law 20.584; these provisions apply only to Chilean Workspaces.