A healthcare team kept sensitive data inside its own boundary
Self-hosting plus right-to-erasure and data-residency controls let a healthcare product adopt modern identity without handing PHI to a third party.
At a glance
The challenge
Patient data carries strict residency and privacy obligations. The team wanted passwordless sign-in for clinicians and a clean way to honour erasure requests, but couldn't route sensitive identities through an external CIAM cloud.
The solution
They ran Qeet ID self-hosted in their own region, so identity data never left their boundary. WebAuthn gave clinicians phishing-resistant login, and right-to-erasure performed an async PII purge while preserving the integrity of the audit trail.
The results
The team modernised authentication on terms their privacy obligations could accommodate, and erasure requests became a built-in workflow rather than a bespoke data project.
“We needed modern passwordless auth without our patient data ever leaving our infrastructure. Self-hosting made that a non-negotiable we could actually meet.”
25,000 monthly active users on the house. Production-grade auth, no credit card, no time limit.
- No credit card
- 25,000 MAU free
- SOC 2 · GDPR ready