Security Architecture & Technical Safeguards
Overview of Nirogyam technical security measures: TLS 1.3 encryption, salted PBKDF2 password hashing, private R2 storage, and zero plaintext credentials.
1. Cloudflare Edge Security & HTTPS Enforcement
Nirogyam is deployed on Cloudflare's enterprise-grade global edge network. All communication is strictly forced over HTTPS with HTTP Strict Transport Security (HSTS). We implement hardened Content Security Policy (CSP) headers, X-Content-Type-Options: nosniff, and strict frame-ancestors protection against clickjacking.
2. Authentication & Zero Plaintext Credential Rule
Nirogyam enforces a strict zero-plaintext rule. User passwords are cryptographically hashed using salted PBKDF2/SHA-256 within the Workers runtime. Sessions are managed using cryptographically secure, HttpOnly, SameSite=Strict cookies to prevent cross-site scripting (XSS) and session hijacking.
3. Private R2 Medical Document Storage
Medical documents and diagnostic dossiers are stored in private Cloudflare R2 object storage buckets. Public access is disabled at the storage boundary. Authorized users access files only through server-side authorized, short-lived pre-signed URLs with mandatory audit logging.
4. Tenant Isolation & Database Security
Our Cloudflare D1 SQL schema strictly isolates patient and hospital records. Hospital users can only query enquiries explicitly assigned to their institution. Admin privileges are role-governed and protected by tamper-evident audit logs.