Skip to main content
Security built for health data

Your data is protected

TorKal is built so your health information stays private, encrypted, and in Israel — and only you decide who can see it.

End-to-End Encryption

All data is encrypted at rest using AES-256-GCM and in transit using TLS 1.3. Provider credentials are encrypted using envelope encryption with automatic key rotation.

Israeli Data Protection

We comply with the Israeli Privacy Protection Act and Ministry of Health regulations. All data is stored on servers located in Israel with geographic redundancy.

Access Controls

Role-based access control (RBAC) with principle of least privilege. Every access to personal data is authenticated, authorized, and logged.

Audit Logging

All sensitive operations are recorded in immutable audit logs with timestamp, user identity, and action context. Logs are retained per regulatory requirements.

Data Residency

Your data stays in Israel. We use SOC 2-compliant cloud infrastructure with data centers in Israel. No data is transferred outside Israeli jurisdiction.

Secure Integration

We connect to Clalit's e-Services portal using official APIs and encrypted sessions. Credentials are never shared with third parties.

Have questions about security?

Contact our security team at security@tor-kal.web.app for details about our security practices.