Principles
- Each clinic’s data belongs to the clinic. We do not sell it or use it for advertising.
- People see only what their role allows.
- We log who changed what and when.
Infrastructure and data location
The Felismed database is hosted on Supabase (United States) and the web app is hosted with a cloud provider in the United States. Each clinic’s data is isolated from other clinics at the database level with row-level access policies.
Conekta processes subscription payment data as a payment sub-processor. Felismed does not store card numbers.
Encryption
- In transit: all connections use HTTPS with TLS 1.2 or higher.
- At rest: the database, files and backups are encrypted.
Access control
- Per-clinic roles (owner, admin, front desk, clinician) with different permissions; for example, front desk cannot read clinical notes.
- Each practitioner sees their own patients; notes can be marked private, and temporary coverage between colleagues is granted and revoked explicitly.
- Signed clinical notes are never edited or deleted: corrections are appended as a new note.
- Schedule privacy mode hides patient names on shared screens.
Backups and continuity
We use the database provider’s backups.
Mexican regulations
- Data protection: processing under the 2025 LFPDPPP. Felismed acts as processor of patient data and the clinic as controller.
- Clinical records: Felismed helps clinics keep records in line with NOM-004-SSA3-2012. Compliance remains each facility’s responsibility.
- Invoicing: CFDI 4.0 stamping through a SAT-authorized certification provider.
Security incidents
We have a procedure to detect, contain and document incidents. If a breach significantly affects people’s rights, we will notify affected clinics without delay so they can inform their patients, as the law requires.
Report a vulnerability
If you find a security issue, email contact@ax9.io with the subject "Security". We will respond within 2 business days. Please do not access third-party data or disclose the issue before we can fix it.
Related documents
Questions about this document? Write to contact@ax9.io