Data Encryption

Curofyx uses strong encryption standards to protect sensitive healthcare and patient data during storage and transmission.

1. Encryption in Transit

All data transmitted between users and our systems is secured using encrypted communication protocols.

  • HTTPS with SSL/TLS encryption
  • Secure API communications
  • Protection against data interception

2. Encryption at Rest

Credentials for every connected review platform — Google, Trustpilot, Doctify, Facebook and more — are encrypted with AES-256-GCM before they ever touch the database. A platform connection being compromised at the database level does not expose a usable access token.

  • AES-256-GCM authenticated encryption for stored platform credentials
  • Passwords hashed with bcrypt, never stored in a reversible form
  • Encryption keys held separately from application data

3. Key Management

Encryption keys are held in restricted server-side configuration, never in application code or version control, and access to them is limited to the systems that need them.

4. Secure Data Handling

Encryption is integrated into all critical workflows, ensuring that sensitive information remains protected throughout its lifecycle.

5. Contact

Email: info@curofyx.com