Trust is the first thing you prescribe.

So we built the software that way too.

  • State Emblem of IndiaMental Healthcare Act, 2017
  • Digital Personal Data Protection Act 2023Digital Personal Data Protection Act, 2023
  • Ayushman Bharat Digital MissionAyushman Bharat Digital Mission
  • Digital IndiaDigital India
  • India CodeIndia Code

The law

What governs the data.

State Emblem of India

Mental Healthcare Act, 2017

Confidential by law, not just by promise.

  • PHI confidential by default, in digital records too
  • Disclosure only on the grounds s.23(2) names
  • Patients can access their own record
Who can access your health recordHealth recordPHI, sealed by defaultYou, the patientYour treating clinicianA court orderAny other partys.23, MHA 2017: disclosure only on the grounds the Act names.

Government, statutory and programme marks are the property of their respective owners and appear here only to identify the laws and standards referenced. Their use does not imply endorsement, certification, or affiliation.

Security controls

How your data is protected.

  1. Data minimisationminimum necessary PHI, purpose-bound at capture
  2. De-identification and tokenisationidentifiers tokenised and vaulted before any model
  3. Encryption in transit (TLS)no plaintext on the wire
  4. Zero-trust access (RBAC + MFA)least privilege, every request authenticated
  5. Data residency (India)single-tenant isolation, Indian region only
  6. Encryption at rest (AES-256)HSM-held keys, kept apart from the data
  7. Consent-bound audit trailtamper-evident chain, every access tied to consent
  8. Break-glass emergency accesssealed override, alarmed and reviewed every time
  9. Retention and cryptographic erasurepolicy-driven retention, then the key is destroyed

Get started

Bring your compliance questions.

We will walk your team through how data is captured, stored, and deleted, end to end.