Security & trust

Your schedule data, on your infrastructure.

Vinta Schedule is self-hosted by design. Run the whole platform in your own environment, keep patient data under your control, and audit every change.

Data residency

Data that never leaves your walls.

Because you host Vinta yourself, scheduling and calendar data lives on infrastructure you own and operate. There is no shared multi-tenant database to reason about.

  • Runs entirely on your own infrastructure
  • No per-seat, per-calendar, or per-booking data sharing
  • You control backups, retention, and residency
  • Bring your own identity and network boundaries

Self-hosted

Your servers · your database · your rules

Controls

Least privilege, all the way down.

Audit logs on everything

Every booking, change, and cancellation is recorded — who did what, when, and to which calendar.

Per-resource access

Grant access at the calendar and resource level, so people and integrations only reach what they should.

Scoped API tokens

Public API tokens are scoped to the exact resources an org admin selects when creating them — nothing more.

Session-only credentials

The docs explorer holds a pasted credential in memory for the tab only — never written to browser storage.

Least-privilege by default

New tokens and connections start with no access. You opt resources in, rather than locking them down after.

Open source

The platform is open — review the code, audit the data flows, and run exactly what you have inspected.

Reporting & policies

Read how we handle data, review the terms of service, or check current platform status. To report a vulnerability, reach the team through our contact page.

Own your scheduling, end to end.

Self-host Vinta Schedule and keep every calendar and booking under your control.