Security
What this product is
Protocol Guide is an EMS protocol reference workflow. Users are instructed not to enter patient identifiers or PHI into free-text search.
It is not an electronic patient care record (ePCR) system and is not sold as a HIPAA-covered ePHI store.
Transport & storage
- HTTPS / TLS for traffic in transit
- Database encryption at rest (provider-managed AES-256 class storage)
- Secrets and API keys live in host env (Railway / Vercel), not in the client bundle
Authentication
- Email/password and OAuth providers where enabled
- Session tokens over HTTPS only
- Admin surfaces require elevated roles
Application controls
- Rate limits on public search and health endpoints
- Security headers (CSP, HSTS, frame denial, etc.) on the web edge
- Webhook and payment paths verify signatures before side effects
Contact
Security questions or vulnerability reports: security@protocolguide.com
Privacy policy: /privacy · Terms: /terms · Support: /support