How Genkō is built

Serious infrastructure.
No complexity for you.

Genkō runs on the same infrastructure trusted by banks, hospitals, and enterprise software — configured so that security and reliability are defaults, not afterthoughts. You don't need to understand any of it. You just need to know it works.

HIPAA-alignedEncrypted at rest & in transitData isolated per practiceNo patient data sold or shared

Patient data that belongs to you

Every practice operates in its own protected space at the database level. Your records are completely yours — separate from every other organization on the platform, by design.

Fast for patients everywhere

Booking pages load in under a second, on any device, from any location. Your portal is the first impression patients get — it should feel instant.

HIPAA-aligned from the ground up

Every infrastructure choice — from database to email to payments — is made with HIPAA-covered entities in mind. Business Associate Agreements available on request.

What makes it work

Every service is here for a reason — and that reason is protecting your practice and your patients.

Supabase

Database security

Your data, completely yours

Each practice operates in its own protected environment at the database level. Records, appointments, and patient details are fully separated from every other organization — enforced by policy, not left to convention.

Powered by PostgreSQL with Row-Level Security on every table.

Stripe

Billing

Payments stay out of our hands

When patients pay for appointments, their card details flow directly to Stripe — the same processor behind Amazon, Shopify, and thousands of healthcare platforms. We never see, store, or touch payment card numbers.

PCI-compliant. Zero card data on Genkō servers.

Vercel

Infrastructure

Always up, always fast

Genkō runs on a global network spanning 50+ regions. Patient-facing booking pages are served from the location closest to each visitor. Deployments happen with no downtime — your practice never goes offline for a software update.

Zero-downtime deploys. Automatic failover built in.

Resend

Email notifications

Reminders that actually land

Appointment confirmations and reminders are sent through purpose-built email infrastructure — not generic SMTP. Proper domain authentication means messages reach the inbox, not the spam folder.

DKIM and SPF configured. No shared sending reputation.

Secure auth

Authentication

Sessions that expire on their own

Every staff and patient login creates a cryptographically signed session that expires automatically. There's no central session database to attack, and a stolen session cannot be used to escalate access beyond what it was issued for.

Short-lived tokens. Cryptographic verification on every request.

Zod

Data integrity

Clean data, always

Every form submission and booking request is fully validated before anything touches the database. Incomplete, misformatted, or unexpected input is rejected at the boundary — corrupt records can't sneak in.

Schema-validated at every API entry point.

Security & compliance

What actually happens to patient data — and what doesn't.

Encryption at rest

All data — patient records, appointments, files — is encrypted at rest using AES-256. Encryption keys are managed by the cloud provider with hardware security modules.

Encryption in transit

Every connection uses TLS 1.2 or higher. HSTS is enforced across all domains — no request can accidentally travel over an unencrypted connection.

Complete data separation

Each practice's records, appointments, and patient details live in their own protected space. Your data is yours exclusively — fully separated from every other organization on the platform.

No patient data used for ads

Patient data is never shared with third parties for advertising, analytics resale, or any purpose beyond operating your practice's scheduling.

HIPAA-aligned infrastructure

Our infrastructure partners (Supabase, Vercel, Stripe) support HIPAA-covered deployments. Business Associate Agreements are available to practices that require them.

Verified integrations only

Webhooks from payment processors and third-party services are verified with cryptographic signatures before processing. Replayed or tampered events are rejected automatically.

Need a Business Associate Agreement?

If your practice operates under HIPAA, we can provide a BAA covering the Genkō platform and our infrastructure partners. Reach out and we'll get it signed quickly.

Ready to put it to work?

Genkō is free to start. No credit card. No IT department required.