Security and data control

Trust begins with precise claims.

AFIYORA describes controls that are verified, separates desktop safeguards from planned cloud architecture, and does not display compliance badges without evidence.

SECURITY PRINCIPLE

Protection should be visible, explainable and proportionate.

Access, data handling, backup and recovery must be reviewed in the deployment context.

Verified desktop controls

Current controls in Inventory Operations.

These controls are available within the current desktop product scope and remain subject to correct customer deployment and administration.

Named access

Administrator, storekeeper, doctor, nurse, therapist, staff and managed operation permissions.

PIN authentication

Named staff authentication with failed-login throttling and responsible-user attribution.

Rolling backups

Automatic backups, export, validated import, database-integrity and checksum validation.

Controlled restore

Restore preview and a safety snapshot before the selected backup is imported.

Movement traceability

Batch, item, adjustment, asset and user activity remain available for operational review.

Trusted LAN boundary

The desktop local server is designed for the clinic network, not direct public-internet exposure.

Planned cloud safeguards

Cloud controls remain part of the roadmap.

The future SaaS architecture is not presented as operational or certified until implementation and evidence are complete.

Coming soon

Tenant isolation

Planned separation between organizations and controlled support access.

Roadmap

Role and entitlement control

Planned module activation, limits, roles, access review and joiner-mover-leaver workflows.

Roadmap

Audit and service visibility

Planned operational audit, system status, background job and security-alert context.

A physician, clinic manager and technology specialist reviewing a proposed action together
HUMAN-GOVERNED AI — ROADMAP

Assistance must stay inside an accountable operating model.

Planned AFIYORA agents are scoped by permission and workflow. Sensitive actions require human review, and the full decision path remains attributable.

Responsible AI controls

The assistant is only one part of the system.

Agentic capabilities require product controls that make context, authority, review and intervention visible to clinic teams.

Bounded purpose

Each assistant has a defined role, data scope and permitted action set.

Reviewable context

People can inspect the information and proposal before approval.

Human authorization

Professional and consequential actions remain under responsible control.

Monitor and pause

Teams can measure quality, handle exceptions and stop automation safely.

CLAIM CONTROL

No unsupported certification language.

AFIYORA does not claim HIPAA, GDPR, DHA, DoH, MOHAP, NABIDH, Malaffi, ISO, SOC 2, PCI, FHIR or HL7 certification or integration without verified evidence.

PRODUCT CLARITYCountry configuration is not regulatory approval.

Language, currency, tax, consent templates or country profiles can support localization, but do not establish legal or clinical compliance by themselves.

Ready for a clearer view?

Bring your security review into the sales process.

Share the deployment model, user roles, network boundary, backup expectations and integration requirements. We will respond with evidence-backed scope and clearly identified gaps.