Skip to content
  • Go live in 5 minutes
  • WhatsApp reminders included
  • Your own clinic website — built in
  • No setup fee · cancel anytime
  • GST-ready billing & Razorpay
  • Built for Indian clinics & hospitals
  • Book a demo
Security

Health records deserve bank-grade care

Your patients trust you with the most private thing they have. This page is a plain account of how that data is protected, where it lives, and what we will never do with it.

The essentials

Six things that are true of every record

Not aspirations — how the platform is built today.

Encrypted in transit

Every connection — browser, mobile, our API, our payment and messaging partners — runs over TLS. Nothing about a patient ever crosses a network in the clear.

Encrypted at rest

Databases and uploaded files are encrypted on disk by the cloud platform. Backups are encrypted with the same keys and stored separately from the live data.

Isolated per clinic

Every record carries the clinic it belongs to, and every query is scoped to the signed-in clinic on the server. One clinic cannot read another’s data even if a request is tampered with.

Access by role

Front desk, doctors, accounts and owners each get their own login with their own permissions. Roles are enforced server-side, so a restricted user cannot reach data by guessing a URL.

Everything is logged

Edits, refunds, permission changes and exports are written to an append-only activity log with the person and the timestamp. You can always answer who did what.

Backed up daily

Automated daily backups with point-in-time recovery, so a mistake at your end or an incident at ours is recoverable rather than final.

Defence in depth

Three layers every record passes through

A single control is a single point of failure. These are independent — one giving way does not open the door.

Layer 1

On the wire

TLS on every connection, HTTP Strict Transport Security so browsers refuse to downgrade, and certificates renewed automatically — including on your own custom domain.

Layer 2

In the database

Managed PostgreSQL in a private network with no public access. Every table that holds clinic data is keyed by clinic, and the application layer refuses a query that does not name one.

Layer 3

At the front desk

Individual accounts, scoped roles, optional two-factor login, and sessions that expire. No shared passwords and no all-access account that everyone uses.

Your data

What we hold, where it sits, and how you get it back

The four questions every clinic should ask a software vendor before signing anything.

What we hold

What a clinic needs to run: patients and their contact details, appointments, prescriptions, uploaded documents, invoices and payment records, plus your staff accounts. We do not buy, sell or enrich patient data, and we never use it to train anything.

Where it lives

On AWS infrastructure in the Mumbai (ap-south-1) region. Your clinic’s data stays in India, which matters both for latency and for the questions your patients are entitled to ask.

Getting it out

Patients, appointments, prescriptions and billing export to CSV whenever you like — including the day you decide to leave. No exit fee, no notice period, no request form.

Deleting it

Close your account and we delete your clinic’s data within 30 days, other than what tax law requires us to retain for invoicing records. Backups age out on their own cycle.

Access control

Who can see what, by default

Every role is adjustable per clinic — this is where each one starts.

RoleCalendarClinical recordsBillingSettings
OwnerFullFullFullFull
DoctorOwn listFullViewNone
ReceptionistFullNoneTake paymentNone
AccountantViewNoneFullBilling only

Two-factor login is available on every account and strongly recommended for owners.

Payments

We never see your patients’ card details

Card and UPI details are entered on Razorpay’s own PCI-DSS certified checkout, not on ours. VaidyaX stores the outcome of a payment — amount, status, reference — and nothing that could be used to charge a card again.

  • No card numbers, CVVs or UPI credentials touch our servers
  • Payment links are single-purpose and expire
  • Webhooks are signature-verified before we trust a single rupee
  • Every payment and refund is written to the audit log

Where we are on formal certification

We are a young company and we would rather tell you this plainly than imply otherwise: VaidyaX is not yet independently certified against ISO 27001 or SOC 2. The controls on this page are real and in place today, and formal certification is on our roadmap as we grow. Our payment processing runs on a PCI-DSS certified provider.

If your organisation needs a security questionnaire completed before you can sign, send it over — we answer them ourselves, honestly, including the parts where the answer is “not yet”.

Shared responsibility

What we do, and what only you can do

Most breaches at small practices are not sophisticated attacks. They are a shared login and a staff member who left in March.

We handle

  • Keeping the platform patched, monitored and available
  • Encrypting data in transit and at rest
  • Enforcing clinic isolation on every request
  • Running and testing daily backups
  • Recording an audit trail you can read
  • Telling you promptly if something goes wrong

Your clinic handles

  • Giving each staff member their own login — never a shared one
  • Choosing roles that match what each person actually needs
  • Turning on two-factor login for owner and admin accounts
  • Removing access the day somebody leaves your clinic
  • Keeping patient consent and clinical practice compliant with your local rules
  • Using a device and network you trust at the front desk

Responsible disclosure

Found something? Tell us before you tell anyone else.

If you believe you have found a vulnerability, email us with enough detail to reproduce it. We will confirm receipt within two working days, keep you updated while we fix it, and credit you if you would like to be credited. We will not take legal action against good-faith research that avoids patient data and does not degrade the service for clinics.

Report a vulnerabilitySecurity questionnaire

Please do not test against a live clinic’s account or real patient records.

Questions your compliance team wants answered?

Send them over. We answer security questionnaires ourselves — usually within a couple of days.

  • Personalised walkthrough
  • No setup fee
  • Cancel anytime