Your patient data. Protected.
ChikitsaOS is built on a security-first foundation — encrypted, audited, and aligned with Indian healthcare regulations including DISHA, with ABDM integration in active development.
AES-256
Encryption standard
military grade
99.9%
Uptime SLA
enterprise guarantee
7 years
Audit log retention
full history
<5 min
Incident detection
real-time alerting
How we protect your data
Every layer of ChikitsaOS is designed with security as a first principle, not an afterthought.
AES-256 Encryption
All patient data is encrypted at rest using AES-256 and in transit using TLS 1.3. Even our team cannot read your patients' data.
Full Audit Logging
Every data access, modification, and deletion is logged with user identity, timestamp, and IP address. 7-year retention for compliance.
RBAC Access Control
Role-based access control ensures each staff member sees only what they need. Doctors, nurses, receptionists, and admins have separate permission sets.
Automated Backups
Incremental backups every 6 hours. Full backups daily. 30-day retention with point-in-time recovery. Stored in a separate geographic region.
Intrusion Detection
Real-time monitoring for unusual access patterns, brute-force attempts, and data exfiltration. Alerts within 5 minutes of anomaly detection.
ABDM Security Standards (in development)
Our in-development ABDM integration is being built to consent management, data minimisation, and purpose limitation requirements from day one.
DISHA Compliant
Aligned with the Digital Information Security in Healthcare Act (DISHA) guidelines for electronic health records.
Indian Data Residency
All patient data stays within India. Hosted on AWS ap-south-1 (Mumbai). No cross-border data transfers.
Security questions? Our team is ready.
We share our security whitepaper, penetration test reports, and compliance documentation with enterprise customers.