Technology
Clinic-first architecture

Technology designed and architected for clinics to excel.

Clinelix isn't a generic BI tool with a stethoscope sticker. Every layer — from connectors to the AI prompt firewall — is built around how healthcare practices in Canada and the United States actually bill, run and grow.

System health
99.94% uptime · trailing 90d
All systems normal
API p95
128ms
Score sync
2.1s
Connectors green
5 / 5
Last incident
47d ago
Architecture

Six layers. One clinic-grade stack.

Every layer is independently observable, versioned, and replaceable. Connectors run sandbox + production in parallel so we can validate every PMS contract before it touches your data.

Clinelix Practice + data ingestion

Run your clinic on Clinelix Practice (built-in PMS) or import via downloadable CSV/XLSX templates. No third-party PMS approvals or OAuth gymnastics required.

Clinelix Practice
CSV templates
XLSX templates
Flinks
Plaid
Ingestion + normalisation

A typed pipeline maps every uploaded dataset into a unified schema. Idempotent loaders, dedupe by UUID, deterministic backfills.

Pydantic
UUID keys
Backfill 24m
Idempotency
Storage

Per-tenant MongoDB databases on Canada Central. Encrypted-at-rest, automated backups, point-in-time recovery.

MongoDB Atlas
CA-Central
AES-256
PITR
Analytics + AI engine

Composable Python service modules compute the five score dimensions. LLMs (Gemini / Claude / GPT) power anomaly detection and NLP, behind a PII-redaction firewall.

Score engine
Anomalies
NLP
PII firewall
API gateway

FastAPI behind rate limiting, audit logging and admin-gated RBAC. Every mutating call is logged with user, IP and request id.

FastAPI
slowapi
Audit log
RBAC
Client

React + Shadcn UI dashboard. Reactive charts, lazy-loaded routes, accessibility-first, fully responsive.

React
Shadcn
Tailwind
WCAG 2.1 AA
Principles

The non-negotiables we build by.

Privacy is a system property, not a checkbox.

Patient PII is auto-redacted before any LLM call. Tokens encrypted at rest with AES-256. Audit log records every sensitive action.

Read-only by design.

Clinelix never has the cryptographic ability to move funds without your approval. Your data lives in your own tenant database, encrypted at rest.

Multi-tenant, single binary.

One battle-tested codebase serves every clinic with tenant isolation enforced at the data layer — no per-customer forks.

Operate-it-yourself observability.

Structured logs, metrics and traces ship to a central observability stack. Customers can see uptime + sync health in the app.

Reproducible by default.

Seeded synthetic data, deterministic backfills and migrations versioned in code mean the same input always produces the same output.

Secrets stay secret.

API tokens are encrypted in the database with a separate KMS-managed key. Rotation is one command away.

How your data gets in

Two paths in. Zero integration approvals.

Run your clinic on Clinelix Practice (our built-in PMS) or keep your existing system and stream data in via CSV / XLSX templates. No PMS vendor approvals. No OAuth gymnastics. Most clinics go live in under 30 minutes.

Clinelix Practice

Built-in PMS · scheduler, notes, claims, inventory.

BYOD templates

CSV / XLSX uploads · re-uploadable, PII-safe.

AI engine

A model-agnostic AI engine, wrapped in a PII firewall.

We don't bet on a single provider. The Emergent Universal LLM Key lets Clinelix route each task to the model best suited for it — without leaking patient data to any of them.

Privacy & safety details
Best model for the task

Anomaly detection runs on Claude for nuanced reasoning; NLP Q&A defaults to Gemini for speed; long-context summaries route to GPT. One key, three providers, zero lock-in.

PII firewall

A deterministic redactor strips patient names, DOBs and identifiers before any prompt leaves your tenant. Aggregated values only.

Full audit log

Every AI chat is recorded with prompt, response, model and latency — invaluable for compliance and reviewers.

Performance & reliability

Numbers your front desk can rely on.

<150ms

p95 API response on the score endpoint

99.9%

targeted monthly uptime SLA

24m

historical PMS data backfilled by default

0

patient PII fields ever sent to LLMs

Standards

Built against the standards your auditor asks about.

PIPEDA

Privacy practices aligned with PIPEDA, including data-subject access and breach notification.

SOC 2 foundations

Controls modelled on SOC 2 Type II criteria; formal audit underway.

WCAG 2.1 AA

Keyboard navigable, screen-reader friendly, contrast-compliant across every screen.

OWASP ASVS L2

Application security verified against OWASP ASVS Level 2 controls, including rate-limiting + input validation.

Want the deep-dive?

We're happy to walk your CTO or IT lead through the architecture, integrations and security posture.