Security
This page describes the safeguards currently in place. Retaiva does not hold a security or privacy certification, and this page is not a certification or audit report.
Hosting and encryption
- Hosted with a major cloud provider in the United States.
- All connections are encrypted.
- Business records and documents are encrypted at rest.
- Documents are not publicly accessible and are available only through the application after an access check.
Access control
- Each business’s records are separated and every request is checked against the signed-in user’s business membership.
- Role-based permissions separate point of sale, management, cost information and pharmacy records. Owners can restrict individual staff further.
- Pharmacist approval, final handover and amendments require a pharmacist registration recorded by the business and a session that completed two-step verification.
- Two-step verification with an authenticator app is available to every user.
- Sign-in attempts are rate limited. Sessions expire and can be revoked.
Records and audit
- Business changes are recorded with the user, action and time. Audit records, prescription history and amendments cannot be altered.
- Dispensed prescriptions cannot be edited; corrections are recorded as amendments that keep the original.
- Views of patient and prescription records and document downloads are logged.
Backups and continuity
- Business records are backed up automatically.
- New releases are tested before they go live and can be rolled back.
Reporting a concern
To report a security vulnerability or suspected incident, contact support@retaivatt.com. Please do not test against other customers’ data. See also the Privacy Policy and Data Processing Addendum.