Skip to content

Security

Patient data deserves serious protection

AfeySync is designed so that each facility’s data stays private, every action is accountable, and only the right people see the right records.

A separate database for every facility

Each facility’s records live in their own database, reached only through its own web address. Every request is checked against the facility it belongs to.

One secure sign-in page

Staff sign in on accounts.afey.co.ke and are handed to their facility with a one-time link that expires within a minute and only works in the same browser.

Two-step verification

Passkeys, authenticator apps, email or SMS codes. Administrators can require it for everyone. Codes are never stored in plain form.

Role-based access

Every screen and every action is checked on the server against the user’s role and branch, never only in the browser.

Records that cannot be quietly changed

Finalised clinical records are locked. Later corrections are recorded as amendments, so the original stays visible.

Full audit trail

Sign-ins and changes to records are logged with who did it and when.

Encrypted everywhere

All traffic uses HTTPS. Integration credentials, such as M-Pesa and insurance keys, are encrypted at rest.

Backups and monitoring

Regular backups and system health monitoring, so your facility keeps working.

Kenya Data Protection Act, 2019

Your facility remains the data controller for its patients’ information. AfeySync processes that information only to provide the service, and gives you the controls you need to meet your obligations: access control, audit trails and data exports.

Ready to run your facility on AfeySync?

Register in about five minutes. Your facility gets its own private database and web address.