Skip to main content

How a hospital's data is kept apart and kept safe.

What the software does today, stated plainly. We list only what is built and running, and we say what is not.

One hospital, one dataset

Every record belongs to exactly one hospital, and every request proves membership before it reads or writes. That includes the audit log and uploaded files. No hospital can see another's data.

Who can do what

Each staff member has one or more roles, and each role lists its permissions. The server checks them on every request; hiding a button is never the control. Denied attempts are written to the audit log.

Accounts

  • Public sign-up is closed. Staff join through an invitation or an operator-created account.
  • Passwords are hashed. We cannot read them.
  • Only the hospital's own members can open its data.

Audit trail

Sensitive actions — deletions, financial corrections, role denials — are logged with who, what and when. The log belongs to the hospital, and staff cannot edit it.

Files

Prescription scans and other uploads sit in a private bucket that is never publicly readable. Each time an authorised member opens one, the software issues a short-lived link.

Money records

Issued invoices are immutable. Corrections are separate documents, so the original always stays on record.

What we do not claim

We are not yet ABDM-certified, and we hold no third-party security certification. We will say so here the day that changes.

Report a problem

If you find a weakness, write to example@gmail.com. Please do not include patient data. For what we collect and why, read the privacy notice.