How Enamela keeps your clinic's data safe
Enamela encrypts your data in transit and at rest, takes daily backups, and limits access by role. If our support team ever needs to look at your clinic's data, we ask for your consent first and log the access. Here's how each part works.
7 days freeNo cardSet up in 10 minutes

What we protect and how
Your clinic's data — patient records, charts, bills, prescriptions — is encrypted in transit, so it can't be read as it moves between your device and our servers, and encrypted at rest, so it's protected on the servers that store it. Enamela is hosted on Supabase (Postgres) and Vercel, both of which run their own security programmes for the infrastructure layer, on top of which we apply our own access controls.
We take daily backups of your clinic's data, so a technical failure doesn't mean losing your records, bills or history. Backups are stored separately from the live database and are part of our regular operations, not something you need to set up yourself.
Who can see what, inside your clinic
Enamela uses role-based permissions: an owner, doctor, receptionist and accountant each see only what their role needs. A receptionist can book and bill without seeing another doctor's private notes; a doctor sees their own patients' charts; only an owner or a role you choose can see combined numbers across branches. You control who on your team has which role from your clinic's settings.
Every clinic's data is kept separate from every other clinic on Enamela. Staff at one clinic, or one branch, cannot see another clinic's or branch's patients, bills or records unless you've explicitly given them access to more than one location.
If our team ever needs to look at your data
Enamela's support team does not browse into your clinic's data by default. If we ever need access to help with a support request or investigate an issue, we ask for your consent first, and that access is recorded in an audit log you can review, along with what was accessed and by whom. You can approve, reject or end that access from your clinic's data access settings at any time.
If something goes wrong
We investigate any reported security issue as a priority and keep affected clinics informed as we learn more.
We aim to fix confirmed issues quickly and tell you what happened, what we did about it, and what changes we made.
You can report a suspected security issue any time at hello@enamela.app.
Where your data is stored
Enamela is a new product, launched in 2026, and we do not currently hold formal security certifications such as SOC 2, ISO 27001 or HIPAA. We're building our practices to a high standard from day one and will share updates here as that work matures.
Data region choices for clinics in Saudi Arabia and the UAE are still being finalised; if data residency in a specific country matters for your clinic, contact us and we'll tell you what's currently possible.
Related
Questions clinics ask
Yes, data is encrypted both in transit, as it moves between your device and our servers, and at rest, as it's stored on our servers hosted on Supabase and Vercel.
Yes, daily backups run automatically as part of how we operate Enamela; you don't need to set anything up or remember to do it yourself.
Only with your consent for a specific support need, and that access is logged. You can review, approve, reject or end data access from your clinic's settings.
Not yet. Enamela is a new product and we don't hold formal certifications at this stage; we'll update this page as that changes.
Enamela runs on Supabase and Vercel. Data region choices for Gulf clinics, such as Saudi Arabia and the UAE, are still being finalised — contact us if residency in a specific country matters for you.
Open your clinic on Enamela today.
Add your chairs and doctors, send your first WhatsApp reminder, and close today's bills before you go home.
7 days freeNo cardSet up in 10 minutes