Data hosted in India, encrypted at rest and in transit, every lab's data isolated from every other lab's, an immutable audit trail, and retention purges on a documented schedule — built to the DPDP Act 2023.
All personal data is stored in India, on cloud infrastructure in the Mumbai region. File storage, queues and fallback OCR are confined to the same region. No personal data is transferred outside India.
Patient phone numbers and other identifying contact data are encrypted with AES-256 at the application layer before storage. Report files are encrypted at rest in object storage; integration tokens and secrets are encrypted too.
All public traffic to the platform is served over HTTPS using modern TLS. The database is not exposed to the public internet.
A multi-tenant architecture with strict tenant isolation — laboratories cannot reach each other's data through the product. Access inside the admin app is role-based.
Sensitive actions — lab operations, messaging activity, queue actions — are recorded in immutable audit records. Consent state changes go to a separate immutable consent log.
Data is purged by category on a defined schedule, with each run recorded for compliance audit. Audit logs and consent logs are never automatically deleted, as DPDP §6 and §8(7) require.
Application services and the database run on Indian cloud infrastructure in the Mumbai region, and no personal data is transferred outside India. Retention is enforced per category — patient contact data, OCR text, AI summaries and message logs each have their own window — and purges run on a schedule that is recorded internally for compliance audit.
Patient consent state is tracked and every change is written to an immutable consent log. Audit and consent records are retained for the periods Indian healthcare and data protection rules require, and a patient can ask for earlier erasure of their personal data, subject to clinical records the laboratory is legally required to keep.
Every AI feature is optional per lab, and none of them send anything to a patient by itself — a person signs first. Turn them off and the rest of the LIS runs exactly as before.
The full list of sub-processors, data categories and retention windows is in the privacy policy; the contractual terms are in the terms of service.
It's hosted in the Mumbai region and never leaves India, in line with the DPDP Act 2023. Patient phone numbers are encrypted, every lab's data is fully separated from every other lab's, and old records are purged automatically on a documented schedule.
Every AI feature is optional per lab. Switch them off and everything else runs exactly as before. No AI ever sends anything to a patient by itself — a person signs first.
Bring last month’s billing file to the demo and we’ll show you exactly what the dashboard would have caught. No credit card, free migration, live in about a week.
Prefer to talk? Call +91 88406 20078 · Mon–Sat, 9am–7pm IST
Tell us about your lab and we’ll get back within 2 hours on a working day.