Security
ClinConnect holds student records, compliance documents, and placement decisions. This page describes how that data is separated, who can reach it, and what the platform records.
Role-based access
Every account has one role, and the role decides which records the account can load at all — the separation is applied when data is fetched, not hidden in the interface.
- Students see their own profile, documents, applications, hours, and evaluations.
- Schools see the students enrolled in their programs and the placements those students hold.
- Clinical sites see the opportunities they posted and the students placed with them.
- Preceptors see the students they supervise.
- Platform administrators see organisation-level records for support and billing.
Accounts and sessions
Accounts sign in with an email address and password. Passwords are stored hashed, never in readable form, and a forgotten password is reset through a single-use link sent to the address on file.
A session lasts seven days and refreshes as you keep using it, so an unattended browser stops being signed in rather than staying open indefinitely.
A reviewable trail
Actions that change someone's standing are recorded with the account that took them and the time they happened — application decisions, hour verification, evaluation submissions, and document review.
That trail is what lets a school answer questions about a placement after the fact, and it cannot be edited away from inside the product.
Reporting a problem
If you believe you have found a security issue, please tell us before disclosing it publicly. We will confirm receipt and keep you updated while we investigate.