Security at ooptify
Practices trust ooptify with sensitive data. This page sets out our security approach — and is deliberately conservative: nothing is claimed here until it has been verified.
Data protection
Practice and patient data is encrypted in transit and at rest. Not every practice system can say this — some store patient records in plain, readable files. If you're comparing platforms, ask each vendor in writing whether your data is encrypted.
Data residency
Practice data is stored in data centres located in the country the practice operates in — for Australian practices, that means your data stays in Australia rather than sitting on servers overseas.
Hosting
The ooptify application is hosted on Vercel, and the database is hosted with Supabase — both established cloud platforms with independently audited security programs (SOC 2). We don't run servers in the practice, so there's no hardware for you to secure, patch or replace.
Access control
Staff start from access levels (administrator, optometrist, senior staff, junior staff), including time-limited accounts for temporary staff. Beyond that, practices can customise who can see each dashboard widget, report and product area — so visibility matches the role, not just a broad tier.
Audit log
Every change to the practice database is recorded — inserts, updates and deletes — with the actor, timestamp, and before/after values. Financial adjustments and refunds carry their own audit metadata. Administrators can search and review this history in the practice audit log report.
Security contact
To report a security concern or vulnerability, get in touch via our contact page.
