Skip to content

Platform & Trust

Compliance, Security & Governance

Security engineering and data governance aligned to India's DPDP Act, GDPR, SOC 2 and ISO 27001 — and to HIPAA and NABH where the data is clinical. Implemented in the system, not in a binder.

Compliance as a property of the system

Policies that live only in documents fail at the first exception. We implement controls where they cannot be bypassed — in the access layer, the audit log and the deployment pipeline.

Every record access is attributable

Who opened this record, when, from where, and under what role. Answering that question in seconds is the difference between a routine audit and an incident. In a hospital that record is a patient chart and the answer is a legal obligation; the engineering is the same wherever the data is sensitive.

What this includes

  • Access control design and least-privilege review
  • Encryption at rest and in transit, with key management
  • Immutable audit logging of every sensitive record access
  • Consent management and data subject request handling
  • Security assessments and remediation programmes

Tell us what you are building.

Describe the problem rather than the solution. We reply with a considered view of what to tackle first — and say plainly if we are not the right fit.