Skip to content
Security & Trust

Patient data, treated as sensitive

Prescriply is built “security by design” — the minimum data necessary, per-doctor isolation, and encryption by default. Here is how that works in plain terms.

In short

Prescriply protects patient data with HTTPS/TLS encryption, bcrypt-hashed passwords with optional authenticator-app two-factor, mobile OTP for registration and the patient portal, and strict per-doctor data isolation. Public prescription links withhold the patient’s national health ID, mobile and address, and the app, database and files are hosted in AWS Asia Pacific (Singapore, ap-southeast-1) with the database on Amazon RDS for PostgreSQL in that same region. AI-assist requests may be processed in other AWS Regions, as the Privacy Policy explains.

Why these choices, in this market: with 185 million mobile connections in Bangladesh (DataReportal, 2025), a prescription is far more likely to be opened on a phone — and passed on to a pharmacy or a relative — than filed in a drawer, which is why the public link withholds the patient's national health ID, mobile number and address. And because the WHO estimates 1 in every 20 patients suffers preventable harm in health care, half of it medication-related (WHO, 2023), a prescription record has to be tamper-evident as well as private: the public link always shows the prescription exactly as it was issued.

Encrypted in transit & at rest

All traffic runs over HTTPS/TLS, and data is encrypted at rest at the infrastructure provider. Nothing sensitive travels or sits in the clear.

One doctor, one vault

Every record is scoped to the owning doctor, and every query is filtered by that scope — so one practice's patients, prescriptions and earnings are never visible to another.

Password + optional two-factor

Doctors sign in with a password and can add authenticator-app (TOTP) two-factor with single-use backup codes; mobile OTP with anti-abuse rate limiting guards registration, password reset and the patient portal.

Privacy by design

We collect the minimum needed. The public prescription link shows the Rx but deliberately withholds the patient's national health ID, mobile number and address.

Known, stable hosting

The app, database and files run in AWS Asia Pacific (Singapore, ap-southeast-1), with the database on Amazon RDS for PostgreSQL in that same region. AI-assist requests may be processed in other AWS Regions, and voice dictation in Chrome is sent to Google for speech recognition; the Privacy Policy describes both.

Money that can't drift

Every fee and settlement is computed in paisa-exact integers — never floating-point — so chamber accounts always reconcile to the last taka.

Least privilege + audit trail

Passwords are hashed with bcrypt, internal access is least-privilege, and security-relevant events are written to an audit trail.

Incident response

We work to detect and prevent incidents, and in a verifiable breach we notify affected users and the authorities without undue delay, in line with applicable law.

The formal statements, in full

This page summarises our posture. For the authoritative detail — controls, sub-processors, data location, cross-border transfer and breach posture — read the full statements.

Found a vulnerability? Please report it to info@prescriply.bd.