
Trust is the first thing you prescribe.
So we built the software that way too.
Mental Healthcare Act, 2017
Digital Personal Data Protection Act, 2023
Ayushman Bharat Digital Mission
Digital India
India Code
The law
What governs the data.

Mental Healthcare Act, 2017
Confidential by law, not just by promise.
- PHI confidential by default, in digital records too
- Disclosure only on the grounds s.23(2) names
- Patients can access their own record
Government, statutory and programme marks are the property of their respective owners and appear here only to identify the laws and standards referenced. Their use does not imply endorsement, certification, or affiliation.
Security controls
How your data is protected.
- Data minimisationminimum necessary PHI, purpose-bound at capture
- De-identification and tokenisationidentifiers tokenised and vaulted before any model
- Encryption in transit (TLS)no plaintext on the wire
- Zero-trust access (RBAC + MFA)least privilege, every request authenticated
- Data residency (India)single-tenant isolation, Indian region only
- Encryption at rest (AES-256)HSM-held keys, kept apart from the data
- Consent-bound audit trailtamper-evident chain, every access tied to consent
- Break-glass emergency accesssealed override, alarmed and reviewed every time
- Retention and cryptographic erasurepolicy-driven retention, then the key is destroyed
Get started
Bring your compliance questions.
We will walk your team through how data is captured, stored, and deleted, end to end.