How a hospital's data is kept apart and kept safe.
What the software does today, stated plainly. We list only what is built and running, and we say what is not.
One hospital, one dataset
Every record belongs to exactly one hospital, and every request proves membership before it reads or writes. That includes the audit log and uploaded files. No hospital can see another's data.
Who can do what
Each staff member has one or more roles, and each role lists its permissions. The server checks them on every request; hiding a button is never the control. Denied attempts are written to the audit log.
Accounts
- Public sign-up is closed. Staff join through an invitation or an operator-created account.
- Passwords are hashed. We cannot read them.
- Only the hospital's own members can open its data.
Audit trail
Sensitive actions — deletions, financial corrections, role denials — are logged with who, what and when. The log belongs to the hospital, and staff cannot edit it.
Files
Prescription scans and other uploads sit in a private bucket that is never publicly readable. Each time an authorised member opens one, the software issues a short-lived link.
Money records
Issued invoices are immutable. Corrections are separate documents, so the original always stays on record.
What we do not claim
We are not yet ABDM-certified, and we hold no third-party security certification. We will say so here the day that changes.
Report a problem
If you find a weakness, write to example@gmail.com. Please do not include patient data. For what we collect and why, read the privacy notice.