Patient data isolated by construction.
Health data is criminal-liability territory under the Data Protection Act. So isolation, audit and an untouchable money ledger aren't features bolted on — they're the substrate the whole platform is built on.
Core security guarantees
Isolated by construction
Hospital A can never read Hospital B. Every table carries the tenant key and forced row-level security; cross-tenant references are structurally impossible, not just policy-forbidden. A 74-test suite proves it on every change.
Role-based access
Roles are data — a permission for every action, re-asserted in the database, not just hidden in the UI. A pharmacist sees pharmacy; a clinician sees the clinic.
Everything is audited
An append-only audit log records who did what, when — including break-the-glass access to a record outside a care relationship, which is justified and rate-limited.
Money can't be edited
Payments are an append-only ledger — a reversal is a new row, never an edit or delete — with idempotency so an M-Pesa double-fire is caught, not double-counted.
MFA for privileged roles
Administrators run with multi-factor authentication enforced; sessions are validated live against membership, never a blindly-trusted token.
Coded from day one
Clinical data carries ICD-11 codes and FHIR-shaped claims — so terminology and interoperability are a data migration later, not a rebuild.
Kenya-first, built to certify.
Data protection (ODPC). Under the Data Protection Act 2019 the facility is the data controller and Salus is the processor. We build for a Data Processing Agreement and explicit, withdrawable patient consent, and default to local hosting while residency rules settle.
DHA HMIS certification.Certification is the gate to SHA contracting — and it's on our critical path, in progress. That's exactly why we lead cash-first: you get real value before certification lands, then switch on SHA claims when it does.
Simulated until credentialed. M-Pesa, eTIMS, SHA and SmartAccess run behind one country-adapter and are simulated on synthetic data today. No real patient record or live transaction is processed until the cost and PHI gates are cleared — deliberately.
Want the detail? We're happy to share our data-protection impact assessment and hazard log with serious design partners. Get in touch →
Security you can certify against.
See Salus on your own workflow in 20 minutes — cash-first, no rip-and-replace, no long contract.