Security
How Licit Note handles security.
Clinics trust Licit Note with patient information, and employers trust its notes. This page explains, in plain English, how the platform protects both. It describes the design; it isn’t a certification or an independent audit.
Data handling
Licit Note handles the information a clinic needs to run its queue and issue notes:
- Staff accounts: names, work email addresses, the clinic, and each person’s role there.
- Patients: the name, South African ID number, mobile number, reason for the visit, and doctor that reception enters.
- Doctors: HPCSA registration number, qualifications, and practice details, so we can verify them.
- Notes: who issued each note, for which patient, when, and any days off.
Passwords are held by our sign in provider in hashed form only; we can’t read them. Information travels over encrypted connections. Licit Note runs on Supabase (database, sign in, file storage, and server functions) and Cloudflare (website and network), which process information only to provide their service to us. They may store it outside South Africa, under protections comparable to POPIA.
Verification security
A note’s QR code and link carry a verification code: 32 random bytes from a cryptographic random number generator, far too many to guess. The database keeps only a SHA-256 hash of that code, so working links can’t be read back out of it.
- Created on the server. Notes are created by a server function, never by the phone. It confirms that the doctor’s HPCSA registration is verified, and that the consultation is assigned to them and in progress, before the note exists.
- Sealed when issued. Each note stores a SHA-256 fingerprint of its contents at the moment it was issued, and the apps can’t edit notes afterwards.
- A narrow public lookup. The check page looks up the one note matching the code on our server, and the page receives only what it shows: the status, initials and surname, days off, the doctor, the clinic, and the dates.
- Reissue replaces, revoke ends. Reissuing gives a note a new code, and the old one stops working at once. Revoking is permanent and can’t be undone.
- One address. Genuine checks open on app.licitnote.com. If a code opens anywhere else, it didn’t come from Licit Note.
Access control
People get access that matches their role, and nothing more.
- Clinic isolation. Row level security in the database limits clinic staff and doctors to their own clinic’s records. The database enforces it, not only the apps.
- Approval before access. Every new clinic is reviewed before it can be used. Staff and doctors who choose a clinic see nothing until its clinic admin approves them.
- Verified doctors only. A doctor can issue, reissue, or revoke notes only once Licit Note has verified their HPCSA registration, and only for their own patients and notes.
- Reception can’t issue notes. Only doctors can issue, reissue, or revoke a note.
- Platform administrators at Permason Technologies can approve or suspend clinics and accounts. They see totals of patients, visits, and notes, never patient details.
- Limits on guessing. The reception app limits repeated sign in and sign up attempts. Doctors can sign out of every device at once if a phone is lost.
Auditability
Important actions are written to the clinic’s activity record: registering a patient, and issuing, reissuing, or revoking a note, each with the account that did it and the time.
- The apps can’t edit or delete the activity record.
- Each entry includes a fingerprint of the entry before it, so a gap or a change would show.
- Internet addresses are never stored in it, only hashes of them.
- The public check counts how many checks happen each day and what they found. It doesn’t record who checked, or which note.
Privacy
A check shows the minimum needed to confirm a note. It never shows the patient’s ID number, phone number, or the reason for the visit. Each app’s Privacy Policy explains exactly what it collects, why, and for how long:
No system is perfectly secure. If a breach affects personal information, we will tell the people and clinics affected, and the Information Regulator, as POPIA requires.
Reporting a security issue
If you think you’ve found a security problem in Licit Note, email support@licitnote.com with the subject “Security report”. Please include:
- What you found, and where: the app, page, or address.
- The steps to reproduce it.
- What someone could do with it.
While you look into it, please don’t access, change, or delete other people’s information, don’t disrupt the service for clinics, and give us reasonable time to fix the problem before you tell anyone else. We read every report.