Built like the regulators are watching — because they are.
Tenelix treats security and audit as the substrate, not a layer. Every clinical action is attributable, every tenancy boundary is enforced at the database, and every customer can choose where their data lives.
Four pillars, end-to-end.
Tenant isolation by design
Standard tenants share a row-isolated database; Enterprise tenants get a dedicated PostgreSQL database. The same application either way — only the connection differs.
PHI access logging
Every read of a patient record emits a structured event. Tenant, user, action, and timestamp — queryable from your audit dashboard.
Three-layer authorization
Every action clears three independent authorization checks — at the route, on the request, and in the service layer — so a single missed guard never exposes data.
Tenant-aware structured logging
Every log line is attributed to its tenant, user, and request. Filter incidents by tenant; every event is queryable and exportable — nothing slips through unattributed.
Choose your blast radius.
Tenelix supports three tenancy modes — standard, enterprise cloud, enterprise self-hosted. The same product runs in all three; only the hosting and isolation change.
| Standard (shared) | Enterprise — Cloud | Enterprise — Self-Hosted | |
|---|---|---|---|
| Database isolation | Row-level isolation per tenant | Dedicated database per tenant | Your own database |
| File storage | Isolated file storage per tenant | Dedicated file storage per tenant | Your own storage, customer-managed |
| Best for | Cost-effective SaaS, small/mid clinics | Large hospitals, strict compliance | Data sovereignty, no-internet sites |
What's actually implemented.
Network & infrastructure
- TLS 1.3 in transit, AES-256 at rest
- Network isolation between application and data tiers
- Encrypted, automated database backups
- Independent penetration testing (planned for GA)
Identity & access
- Role-based access (14 modules, three layers of authorization)
- Two-factor authentication (authenticator app) with break-glass recovery codes
- Magic-link patient portal authentication
- Configurable session timeout per tenant
Audit & forensics
- Append-only PHI access log
- Override actions recorded with a labelled reason (e.g., [CLEARED WITHOUT PAYMENT])
- Lifecycle audit on forms, prescriptions, invoices
- Tenant-scoped audit logs, queryable and exportable
Data residency
- Cloud (default): hosted in Cape Town (af-south-1); additional regions on the roadmap
- Self-hosted: customer's own infrastructure, no data leaves the network
- File storage on your own infrastructure (local disk, or an S3-compatible store)
- Backup and DR runbooks shipped with the self-hosted stack
Where we are. Where we're going.
We publish status, not promises. NDPA 2023 controls are implemented today; HIPAA, GDPR, SOC 2 Type II, and ISO 27001 are sequenced across 2026–2027.
Found a vulnerability?
We welcome responsible disclosure. Email security@tenelix.com with steps to reproduce and we'll follow up. A formal coordinated-disclosure program with published response targets is coming as we approach GA.
Ready when you are
Reviewing Tenelix for your clinic?
Request our security documentation and we'll walk your team through how your data is isolated, encrypted, and audited.