ENTERPRISE SECURITY & REGULATORY COMPLIANCE

Enterprise Security, Privacy & Data Protection

Architected with official Kuwait CITRA regulatory licensing, end-to-end encryption, multi-tenant PostgreSQL Row-Level Security, and operational audit logs.

CITRA Approval No. 981 ISIC 631100 Data Processing PostgreSQL Row-Level Security TLS 1.3 & AES-256
OFFICIAL LICENSE
State of Kuwait • CITRA Regulatory FrameworkApproval No. 981 • Dated 15 July 2026

Licensed for Data Processing and Web Hosting Services (Activity 631100)

AUTONIQUE holds official regulatory approval from the Communication & Information Technology Regulatory Authority (CITRA Approval No. 981, dated 15 July 2026) under Activity Code 631100 (Data Processing and Web Hosting). Our cloud platform operates in statutory compliance with the Kuwait CITRA Data Privacy Protection Regulation (Regulation No. 26 of 2024), providing healthcare and beauty enterprises with a fully certified and legally compliant data processor in Kuwait.

SECURITY PILLARS

Four Layers of Enterprise Data Protection

Engineered to protect appointment schedules and customer communications with strict tenant boundaries and access controls.

Multi-Tenant Isolation

Logical Partitioning & Row-Level Security

Strict database-level Row-Level Security (RLS) ensuring absolute data isolation between accounts, with native multi-campus hospital and branch hierarchy.

Access Governance

Granular Role-Based Access Control

Granular least-privilege permissions tailored for Doctors, Nurses, Front-Desk Receptionists, and Staff to prevent unauthorized access.

Audit Trail

Operational Activity & Audit Logging

Timestamped event stream capturing every appointment update, booking confirmation, and human chat takeover for total front-desk accountability.

Cloud Database

Managed Cloud Database & Encryption

Managed PostgreSQL cloud database with encrypted data in-transit (TLS 1.3) and at-rest (AES-256), backed by hardened tenant security.

ACCESS CONTROL

Role-Based Access Control Matrix (RBAC)

Enforcing strict least-privilege governance so every staff member accesses only role-essential workflows.

Role / PersonaPermission ScopeWhatsApp ChatCalendar & BookingActivity Logs
Doctors & PractitionersPatient Appointments & Direct ScheduleView OnlyFull AccessSelf Logs
Nurses & Care StaffPatient Prep & Clinic FlowRestrictedStatus UpdateView
Front-Desk ReceptionistsChat Takeover & SchedulingTakeover & SendBook & MoveShift Logs
Management & AdminsSystem Settings & OverviewFull AccessFull AccessExport Logs
AUDIT & LOGGING

Operational Activity & Front-Desk Audit Trail

Timestamped activity trail recording booking confirmations, schedule modifications, and receptionist takeovers.

Activity Logging Active
Dr. Ahmed Al-Mansouri
Viewed upcoming patient schedule14:02:11 GMT+3
Logged
Receptionist Sarah
1-Click WhatsApp Human Takeover (AI Paused)14:04:35 GMT+3
Logged
System Engine
Confirmed Appointment Booking -> Monday, 11:20 AM14:15:02 GMT+3
Logged
TECHNICAL PROTOCOLS

High Availability, Web Defense & Data Rights

Availability

Automated Backups & High Availability

Automated database backups and disaster recovery procedures ensuring continuous availability for appointment operations.

App Defense

Rate Limiting, CSRF & DDoS Mitigation

Automated request throttling, webhook signature verification, strict Content Security Policy (CSP), and cross-site request forgery protection.

Enterprise Messaging

Enterprise Twilio for WhatsApp Business Messaging

Encrypted enterprise routing via Twilio official WhatsApp Business messaging infrastructure, ensuring verified uptime, high deliverability, and reliable number protection.

Data Rights

Tenant Data Ownership & Retention Control

All records remain the exclusive property of the subscribing clinic or salon. Full data export and configurable automated deletion upon contract conclusion.

SECURITY DESK

Need an Enterprise Security Assessment or DPA?

Our compliance desk is available to review vendor risk questionnaires, execute Data Processing Agreements (DPA), or sign enterprise SLAs.