Trust

Security overview

This page describes how Txtur is built today. It is not a certification claim (for example HIPAA, SOC 2, or ISO). Ask [email protected] if you need a deeper review for your organization.

Invite-only access

Public self-registration is disabled. New members join by invitation so workspaces stay intentional. That reduces anonymous account sprawl and makes it clearer who belongs in a clinic or care-team workspace.

Authentication and permissions

Members sign in with account credentials. Features are gated by roles and scopes (for example who can message, create documents, or manage access). Admins can keep sensitive surfaces limited to the people who need them instead of opening every tool to every account by default.

Transport security

The marketing site and application are served over HTTPS. API and realtime connections use TLS through our edge and origin configuration. Browsers should always reach Txtur over encrypted transport on the public hosts we operate.

Data separation

The public marketing site (txtur.me) is separate from the application (app.txtur.me) and API (api.txtur.me). Search engines are directed to index only public marketing pages. Signed-in product traffic stays on the app host so crawlers are not treated as the primary audience for private UI.

Operational posture

We aim for clear boundaries: public pages explain the product; private workspaces require authentication; uploads and messages belong to the account and workspace context that created them. Details about account data, messages, and cookies are documented in our Privacy Policy.

If your procurement process needs a written summary of hosts, access model, and what is (and is not) claimed on this page, email us and we will point you to the current public documentation first.

Questions

Security or vendor review: [email protected]. Tell us what your organization needs to evaluate (architecture overview, subprocessors, or access model) and we will respond with accurate information — without overstating certifications we have not completed.

Back to features