Rolvina

Security and your data

Your clinic's records are yours. Here is how Rolvina keeps them separate, private and accountable.

Every clinic in its own database

Each clinic's records live in their own database file, never mixed with another clinic's. The software refuses, at its core, any request that tries to reach a different clinic's file — and it is tested to prove it.

A tamper-evident audit trail

Every change — a note signed, a charge voided, a drug wasted — is recorded with who, when and from where, in a chain where each entry seals the one before. Altering history breaks the chain, and Rolvina checks it.

Records that cannot be quietly changed

Signed notes lock; corrections are addenda. Finalized invoices never change — they are voided and reissued. Controlled-drug waste cannot be recorded without a witness who signs in with their own password.

Sign-in and sessions

Each clinic is its own web address, and a sign-in is valid only there. Passwords are stored as one-way hashes; repeated failures are slowed and blocked; every form is protected against cross-site requests; pages cannot load outside content.

AI, by your choice

AI note drafting uses a model that runs on Rolvina's own servers — your notes are not sent to an outside AI company. A clinic can choose a cloud model instead with its own key, or turn AI off.

Payments

Card payments go through Stripe. Rolvina never sees or stores card numbers.

On your own Mac

A clinic can run Rolvina on a Mac in its own building, served over encrypted HTTPS on the clinic network, with a backup every night.

Coming next

Encryption of every clinic's database at rest, continuous off-site backup with point-in-time restore, and authenticator-app two-step sign-in are the next security work on our roadmap.