Security summary
For hospital IT and data-protection reviewers · 01/10/2026
This is a short summary. The full document, with the threat model and every limitation, is on the releases page: Security and privacy (full).
What is stored, and where
- Ward-round working notes for one clinician: patient identifiers (name, MRN, bed, age, sex, nationality), admission details, history, problems, medications, results, procedures, consults, progress notes, hospital course and flags.
- Only on the user's own device, in the app's private storage. One user per install; no shared database, no accounts.
- No server, no cloud sync, no analytics, no crash reporting, no remote logging. The developer has no access to any data and cannot recover it.
Encryption at rest
- The database is encrypted with SQLCipher 4 (AES-256). The app refuses to open it without SQLCipher, so it never falls back to a plain file.
- A random 256-bit data key is generated on the device and kept in the operating system's secure storage: Android Keystore, iOS Keychain (this device only, never synced), Windows Credential Manager or macOS Keychain.
- Android system backup is disabled for the app; on iPhone the app's files are excluded from iCloud and Finder backups.
Keys and recovery
- Optional passphrase (at least 12 characters) plus a recovery key shown once. Either one unlocks the data key (PBKDF2-SHA256, 600,000 iterations, AES-256-GCM key wrapping).
- Without a passphrase the key exists only in the device's secure storage; if that is lost, the data cannot be opened — the app offers to start fresh and restore a backup. Nothing is deleted.
App lock
- Optional biometric or 6-digit PIN lock, with automatic lock after a chosen time away (or without keyboard and mouse use on a computer). Increasing waits after wrong PINs; never wipes data.
- The lock is an in-app gate: it stops people using the app, not an attacker who can run code as the app on an unlocked, compromised device.
Network
- The phone apps make no network requests. The Android app has no Internet permission, so the operating system blocks any connection.
- The computer app's only network use is the Check for updates button, and only when pressed. Updates are verified against a signature key built into the app before they install. Mac builds are signed with an Apple Developer ID and notarised by Apple.
Transfer and backups
- Data leaves the device only when the user makes a .roundxer file: AES-256-GCM, key wrapped by the passphrase or recovery key — or, when sharing selected patients with a colleague, by a one-time passphrase.
- Import merges by record (newest wins) and never deletes local records; "Replace everything" needs typed confirmation and keeps a safety copy.
Known limitations
- Screenshots are allowed, and exported text and PDFs are not encrypted — users should share them only through channels the hospital allows.
- The Windows installer is not yet code-signed (Windows SmartScreen warns on first run).
- Retention is the user's responsibility; optional auto-delete of discharged patients (7, 30 or 90 days) is available.
Questions from IT or data-protection teams are welcome: support@roundxer.com.