Role-based access control
Permissions are evaluated server-side; the interface only mirrors them.
- Roles stored separately from profiles
- Server-evaluated permissions
Security
Steritrack states only what is implemented. Access rules, tenant isolation and audit immutability are enforced server-side, so hiding a button is never the security mechanism.
Permissions are evaluated server-side; the interface only mirrors them.
Every operational table is scoped to an organization by database policy.
Audit and traceability events are append-only, including for privileged roles.
No automatic release. A qualified human validates before a set returns to use.
The data model has no patient identity fields; cases use opaque references only.
The public review environment is isolated and has zero write capability.
Steritrack does not claim ISO 27001, SOC 2 or HDS certification, and does not currently advertise MFA or SSO. Only the controls listed above are implemented.