🎉 Now from ₹299/month — full LIS, analyser integration and WhatsApp reports. See plans
Security & compliance

How Raydian LIS keeps lab and patient data safe

Data hosted in India, encrypted at rest and in transit, every lab's data isolated from every other lab's, an immutable audit trail, and retention purges on a documented schedule — built to the DPDP Act 2023.

The controls

What protects the data

Each of these is set out in full in our privacy policy.

Data stays in India

All personal data is stored in India, on cloud infrastructure in the Mumbai region. File storage, queues and fallback OCR are confined to the same region. No personal data is transferred outside India.

Encrypted at rest

Patient phone numbers and other identifying contact data are encrypted with AES-256 at the application layer before storage. Report files are encrypted at rest in object storage; integration tokens and secrets are encrypted too.

Encrypted in transit

All public traffic to the platform is served over HTTPS using modern TLS. The database is not exposed to the public internet.

Tenant isolation

A multi-tenant architecture with strict tenant isolation — laboratories cannot reach each other's data through the product. Access inside the admin app is role-based.

Immutable audit trail

Sensitive actions — lab operations, messaging activity, queue actions — are recorded in immutable audit records. Consent state changes go to a separate immutable consent log.

Documented retention

Data is purged by category on a defined schedule, with each run recorded for compliance audit. Audit logs and consent logs are never automatically deleted, as DPDP §6 and §8(7) require.

Built for the DPDP Act 2023

Application services and the database run on Indian cloud infrastructure in the Mumbai region, and no personal data is transferred outside India. Retention is enforced per category — patient contact data, OCR text, AI summaries and message logs each have their own window — and purges run on a schedule that is recorded internally for compliance audit.

Patient consent state is tracked and every change is written to an immutable consent log. Audit and consent records are retained for the periods Indian healthcare and data protection rules require, and a patient can ask for earlier erasure of their personal data, subject to clinical records the laboratory is legally required to keep.

AI never acts on its own

Every AI feature is optional per lab, and none of them send anything to a patient by itself — a person signs first. Turn them off and the rest of the LIS runs exactly as before.

Read the detail

The full list of sub-processors, data categories and retention windows is in the privacy policy; the contractual terms are in the terms of service.

FAQ

Questions about security

Is our patient data safe?

It's hosted in the Mumbai region and never leaves India, in line with the DPDP Act 2023. Patient phone numbers are encrypted, every lab's data is fully separated from every other lab's, and old records are purged automatically on a documented schedule.

Can we turn the AI features off?

Every AI feature is optional per lab. Switch them off and everything else runs exactly as before. No AI ever sends anything to a patient by itself — a person signs first.

Data stays in India AES-256 at rest DPDP Act 2023

Ask the security questions on the demo call

Bring last month’s billing file to the demo and we’ll show you exactly what the dashboard would have caught. No credit card, free migration, live in about a week.

Prefer to talk? Call +91 88406 20078 · Mon–Sat, 9am–7pm IST

Book your free demo

Tell us about your lab and we’ll get back within 2 hours on a working day.

We use your details only to contact you about Raydian LIS.