Security
Security built into every layer
Health records deserve stronger protection than a typical account. Here's what runs underneath every Synk Health record.
Data protection
Encryption at rest
All uploaded documents are encrypted at rest (AES-256) before storage.
Malware scanning
Every uploaded file is scanned for malware before it's accepted into storage.
Consent capture
Privacy notice and terms acceptance is captured, versioned and timestamped at registration.
Access control
Role-based access
Admin, manager, support and lab-partner roles each see only what their role requires.
MFA for privileged accounts
Multi-factor authentication is enforced for all admin, lab staff and clinical reviewer accounts.
Immutable audit log
Every access to and modification of a health record is logged, timestamped and cannot be altered.
Biometric app lock
On the Synk Health mobile app, Face ID or fingerprint unlock protects your health passport even if your phone is unlocked.
Compliance
- Aligned with Ghana's Data Protection Act, 2012 (Act 843)
- Account deletion and data export available on request
- Results only surface to members after authorized lab validation
- Time-limited, revocable sharing — nothing is shared indefinitely