Security
We help you keep your practice secure and meet provincial and federal privacy regulations. Colib's security features protect your data at every level and help your practice meet its PHIPA, PIPEDA, LPRPSP, HIA, PIPA and Loi 25 obligations. Compliance also depends on your own policies and practices. We take all the necessary steps to ensure your practice data is always safe and secure.
Last updated: 2026-09-18
Security is a top priority for Colib
Administrators and practitioners each access Colib using their own account secured by a username and password. If an account has multiple users, administrators can control access permissions for each user, which includes control of accessing patient charts & schedule records and modification/read only rights.
Practitioners, staff and clients can all require a six-digit code, sent to their email address, in addition to their password. For clinics located in Quebec this second step is mandatory for everyone -- practitioners, staff and clients, on Colib and on the client portal -- and cannot be turned off; the same rule applies to Colib's own staff accounts. When two-factor authentication is active, signing in with a Google account also requires the code: Google never replaces the second factor.
Passwords must be 12 to 80 characters long and combine uppercase letters, lowercase letters, digits and a special character. Every new password is also checked against public databases of leaked passwords: only a short fragment of its fingerprint leaves our servers, never the password itself. The last five passwords of an account cannot be reused.
Every successful and failed sign-in is recorded in your security journal. A sign-in from a device we have never seen triggers an email to the account holder with the date, the device and the address. After five wrong passwords the account is locked for 30 minutes and an alert is emailed; no verification code is sent while the lock lasts, and resetting the password unlocks the account immediately. A wrong verification code counts as a failed attempt as well. Unusual volumes of failed sign-ins, lockouts or blocked requests raise an alert to Colib's team, which reviews them daily.
To tell a familiar sign-in from an unusual one, we keep the devices and the addresses used by each account. The address is stored encrypted, never in clear text, a device is forgotten after one year without use, and everything is erased when the account is deleted.
You may restrict access to the clinic's administration area to specific IP addresses, for example only from your clinic (available on the Practice Pro plan).
Each clinic chooses its inactivity delay under Settings > Security: 15, 30, 60, 90, 120 or 180 minutes, 180 by default. Once the delay is reached, users are signed out on the server side, so a screen left open cannot expose a file. On the client portal the delay is 180 minutes.
Under Settings > Team you see the last sign-in of every member of your clinic, and any account with no sign-in for 90 days is flagged so that you can revoke it. The list can be exported to Excel to document your periodic access reviews.
Every time a practitioner views, creates, updates, deletes or downloads a record item, an entry is created. Entries carry the date, the user, the device and the IP address, and can be filtered by user, client, period, domain or type of action. What your clients do on the client portal is recorded in a second journal: sign-ins, documents viewed or downloaded, invoices, forms, messages and appointments, with one record per clinic. Both journals are available on the Audit log page, to the administrator and to any team member granted the audit-log permission, with an Excel and CSV export; the team journal is kept for 3 years and the client portal journal for 18 months.
When our support team works inside your clinic, its actions are recorded exactly like those of your own users and remain visible to you: nothing is hidden from your journal. What our team does in Colib's own administration area is recorded in a separate journal reserved for that purpose.
Access to the audit log is a dedicated permission that the clinic administrator grants member by member. Security events (failed sign-ins, lockouts, blocked requests, sign-ins from new devices, exports, deletions) are reviewed daily and raise alerts to Colib's security officer.
On the client portal, each client has a « My access log » tab listing their own sign-ins and every action on their data for the last 18 months. From that same tab they can download all their data in a single ZIP archive: profile, access log, appointments, invoices, documents, forms, notes and messages, their consents, their waiting-list requests, programs, gift certificates and their payment methods (last four digits only), clinic by clinic. The portal's security page explains in plain language how their information is protected and who to contact.
Consents given by your clients (online booking terms and cancellation policy, text-message reminders, parent or guardian of a minor, form attestations) are recorded with the exact text shown, its version, the date and the encrypted IP address, and are visible in the client record.
Data travels between your device and our servers over TLS 1.2 or 1.3 only; older protocols are refused. Sensitive fields are encrypted again with AES-256 in our databases. Files placed in a client record are encrypted by the application before being stored on private storage, which AWS also encrypts server-side. Audio sent for transcription goes to that private storage and is deleted once transcribed. Only content a clinic publishes itself (logo, gallery images) is public. Our databases and files are located exclusively in Canada, in the AWS Canada (Montreal) region, ca-central-1.
Every file uploaded to Colib is scanned for malware in memory, before it is encrypted and stored. An infected file is refused and raises a security alert.
With Colib, your data is backed up every day on our servers, so you never need to worry about losing practice data. There's no need for finicky backup hard-drives or difficult recoveries.
Telehealth transcription runs on a model hosted inside Colib's own AWS infrastructure in Canada, and note drafts are produced through the Amazon Bedrock managed service. Generation uses the Claude Sonnet 4.6 model for every clinic: the data stays stored in Canada, and the request may transit through, and be processed in, the United States, with nothing kept there. Every draft carries the name of the model that wrote it, and in Quebec the client must tick a consent box before joining a telehealth session when an AI-assisted note is planned: without that consent the session cannot be joined. A transcript kept at your request stays in the record as a clinical working document, for as long as you keep the record. Each clinic can turn the rewriting assistant, form extraction and voice dictation on or off in its settings, and Colib can suspend any AI feature centrally. Read our artificial intelligence policy.
Colib implements multiple layers of defense against malicious attacks. Our platform includes Cross-Site Scripting (XSS) protection to prevent injection of harmful scripts, as well as rate limiting mechanisms to guard against brute-force and denial-of-service attempts. Our pages are served with a Content Security Policy, a Permissions-Policy that restricts access to the camera and the microphone, and HSTS, which forces every connection to use HTTPS.
Our software dependencies are audited against known vulnerability advisories, and a moderate, high or critical vulnerability breaks the build of the components concerned. Our encryption is covered by automated tests on both applications, and technical error logs mask the contents of forms by default: only technical values such as identifiers and dates are kept readable.
We regularly commission independent, third-party penetration tests to proactively identify and address potential vulnerabilities. These assessments are conducted by certified external security firms to ensure an unbiased evaluation of our infrastructure and application security. Our most recent penetration test was completed in April 2026; penetration tests are repeated at least once a year.
No credit card data is stored onto our platform. When you enter credit card information into our platform, Colib creates and keeps a token that can be used to reference that information. The card number is transmitted to Stripe, our PCI DSS-certified payment partner, through an encrypted channel and is never written to our systems; Colib stores only the token, the last four digits, the expiry date and the card's country.
We conduct annual training sessions for all company employees. During these sessions, we communicate to our staff our clear procedures in place to handle and report any suspicious activity to our Chief Privacy Officer.
The person in charge of the protection of personal information at Colib is: Thibault Bréboin, Privacy Officer, Colib Technology Inc., thibault@colib.io. Requests and complaints are handled as described in our privacy policy.
Colib aims for level AA of the WCAG 2.2 accessibility guidelines. Read our accessibility statement.