Security
How accounts, access and data are protected, stated as what the platform does today.
Single sign-on
Staff can sign in with Google Workspace or Microsoft Entra ID, so your organization's own account controls and offboarding apply. Type a work email address on the sign-in page and it offers that organization's sign-in. The answer depends only on the part after the @, so it reveals nothing about who has an account.
Passwords, hashed
Passwords are stored only as bcrypt hashes. They need eight characters with an uppercase letter, a number and a symbol, cannot contain the person's name, and cannot repeat any of the last three.
Lockout on guessing
Repeated failed sign-ins lock the attempt out: eight failures on one account from one address, twenty-five on one account from anywhere, or fifty from one address, within fifteen minutes.
Two-step sign-in
Anyone who signs in with a password can add a six-digit code from an authenticator app, with ten single-use recovery codes for a lost phone. An organization can require it of everyone. Work-account sign-ins use the workspace's own second step.
Sessions you control
The session cookie cannot be read by scripts, travels only over secure connections and ends when the browser closes. Active sessions can be listed and revoked.
Sign-out when idle
Clinic computers are shared, so a session ends after 30 minutes without activity. A warning appears two minutes ahead, and activity in any open tab counts.
Least access
Four roles, from learner to administrator. Supervisors see only the teams they supervise, and every organization is walled off from every other.
A record of changes
Administrative actions are written to an audit log with who did it and from where. When support staff view the platform as a user to help them, that is recorded too.
Deletion that finishes
A deleted account is removed permanently after 14 days, and an organization that leaves can have all of its data removed.
No patient data by design
The platform trains staff and never asks for patient information, which keeps protected health information out of it.
Locked-down pages
Every page is served over HTTPS only, with a content security policy that names each outside service a page may load. Other sites cannot frame the platform, and nothing records sessions.
Verified releases
Every release runs more than 210 automated test files first. After upload, the release checks the live server file by file against what was built, and fails if anything does not match.
Found a security issue? Tell us at info@ophthalmicacademy.us and we will respond promptly.