Security Policy

Last updated: June 2026

1. Introduction

The DrOnline.io platform is created, hosted and managed by Digital Commercial Brokerage and Trading Services (the Platform Operator), with its registered office at Al Jazeera Tower, Building 186, Street 836, Zone 61, West Bay, Doha, State of Qatar. All personal and medical data processed through the platform is controlled and stored under the authority of Royal Link Healthcare Services (the Data Controller). This Security Policy describes the technical and organisational measures used to protect the platform and the personal and medical information processed through it.

Security is a continuous discipline. The controls below are reviewed and updated as the threat landscape and our service evolve.

2. Encryption

  • In transit: all traffic between your device and the platform, and between the platform and our service providers, is protected with TLS 1.2 or higher.
  • At rest: production database storage is encrypted at the disk level. Object storage for photographs and identity documents is encrypted at rest by the cloud provider.
  • Secrets: credentials, API keys and signing material are stored in a managed secrets vault and rotated periodically.

3. Access control

  • Role-based access control (patient, doctor, clinic admin, pharmacy, driver, platform admin). Each role only sees the data it needs to perform its function.
  • Patient records can be viewed by the treating doctor, Royal Link Healthcare Services's authorised staff, the dispensing pharmacy (medication-only view), and the assigned driver (delivery-only view).
  • Multi-factor authentication is required for clinical, administrative and driver staff accounts.
  • Database row-level security policies enforce these access boundaries at the data layer, not just the application layer.
  • Access to medical records is logged and reviewable.

4. Authentication

  • Patient sign-in uses email or WhatsApp one-time passcodes.
  • Sessions use secure, HTTP-only, signed tokens with reasonable expiry.
  • Password resets and email verification flows are time-limited and single-use.
  • We monitor for credential stuffing, abnormal sign-in patterns, and abusive traffic.

5. Application security

  • Server-side validation of all sensitive inputs, including pricing, identity checks and order shape.
  • Defence-in-depth against common web vulnerabilities (OWASP Top 10) including input sanitisation, parameterised queries, content-security headers and CSRF protections.
  • Dependencies are tracked and patched; security updates are applied promptly.
  • Code changes go through peer review before reaching production.

6. Network and infrastructure

  • Hosting on hardened, audited cloud infrastructure with provider-level DDoS protection.
  • Production environments are isolated from development and staging environments.
  • Public endpoints sit behind a CDN with web application firewall capabilities.
  • Backups are encrypted and tested; see the Data Retention Policy.

7. Vendor and sub-processor management

We use a small set of vetted service providers for cloud hosting, payments, delivery, messaging, AI image generation, and email. Each provider is bound by contractual data-protection terms requiring them to maintain security appropriate to the data they process and to notify us promptly of any incident.

8. Logging and monitoring

  • Application and infrastructure logs are collected for security and reliability.
  • Unusual activity (failed sign-ins, abnormal data access, error spikes) triggers alerts to the platform team.
  • Log retention is described in the Data Retention Policy.

9. Incident response

We maintain an incident-response process covering detection, containment, investigation, eradication, recovery, and post-incident review. If a personal data breach is confirmed and is likely to result in risk to your rights, we will notify the relevant Qatar regulator and affected users without undue delay and within the timeframes required by law.

10. Responsible disclosure

Security researchers and users who believe they have found a vulnerability are asked to report it to security@dronline.io rather than disclosing it publicly. We will acknowledge legitimate reports promptly, work to remediate, and credit the reporter where appropriate. Please do not access or alter data that is not your own.

11. Patient and provider responsibilities

The medical record itself is the responsibility of Royal Link Healthcare Services. Royal Link Healthcare Services and each treating doctor is responsible for safeguarding the credentials and devices they use to access the platform. Patients are asked to keep their own credentials confidential and to report any suspected account compromise.

12. Contact

Security: security@dronline.io
Privacy: privacy@dronline.io

Digital Commercial Brokerage and Trading Services, Al Jazeera Tower, Building 186, Street 836, Zone 61, West Bay, Doha, State of Qatar