Health records deserve bank-grade care
Your patients trust you with the most private thing they have. This page is a plain account of how that data is protected, where it lives, and what we will never do with it.
Six things that are true of every record
Not aspirations — how the platform is built today.
Encrypted in transit
Every connection — browser, mobile, our API, our payment and messaging partners — runs over TLS. Nothing about a patient ever crosses a network in the clear.
Encrypted at rest
Databases and uploaded files are encrypted on disk by the cloud platform. Backups are encrypted with the same keys and stored separately from the live data.
Isolated per clinic
Every record carries the clinic it belongs to, and every query is scoped to the signed-in clinic on the server. One clinic cannot read another’s data even if a request is tampered with.
Access by role
Front desk, doctors, accounts and owners each get their own login with their own permissions. Roles are enforced server-side, so a restricted user cannot reach data by guessing a URL.
Everything is logged
Edits, refunds, permission changes and exports are written to an append-only activity log with the person and the timestamp. You can always answer who did what.
Backed up daily
Automated daily backups with point-in-time recovery, so a mistake at your end or an incident at ours is recoverable rather than final.
Three layers every record passes through
A single control is a single point of failure. These are independent — one giving way does not open the door.
On the wire
TLS on every connection, HTTP Strict Transport Security so browsers refuse to downgrade, and certificates renewed automatically — including on your own custom domain.
In the database
Managed PostgreSQL in a private network with no public access. Every table that holds clinic data is keyed by clinic, and the application layer refuses a query that does not name one.
At the front desk
Individual accounts, scoped roles, optional two-factor login, and sessions that expire. No shared passwords and no all-access account that everyone uses.
What we hold, where it sits, and how you get it back
The four questions every clinic should ask a software vendor before signing anything.
What we hold
What a clinic needs to run: patients and their contact details, appointments, prescriptions, uploaded documents, invoices and payment records, plus your staff accounts. We do not buy, sell or enrich patient data, and we never use it to train anything.
Where it lives
On AWS infrastructure in the Mumbai (ap-south-1) region. Your clinic’s data stays in India, which matters both for latency and for the questions your patients are entitled to ask.
Getting it out
Patients, appointments, prescriptions and billing export to CSV whenever you like — including the day you decide to leave. No exit fee, no notice period, no request form.
Deleting it
Close your account and we delete your clinic’s data within 30 days, other than what tax law requires us to retain for invoicing records. Backups age out on their own cycle.
Who can see what, by default
Every role is adjustable per clinic — this is where each one starts.
| Role | Calendar | Clinical records | Billing | Settings |
|---|---|---|---|---|
| Owner | Full | Full | Full | Full |
| Doctor | Own list | Full | View | None |
| Receptionist | Full | None | Take payment | None |
| Accountant | View | None | Full | Billing only |
Two-factor login is available on every account and strongly recommended for owners.
We never see your patients’ card details
Card and UPI details are entered on Razorpay’s own PCI-DSS certified checkout, not on ours. VaidyaX stores the outcome of a payment — amount, status, reference — and nothing that could be used to charge a card again.
- No card numbers, CVVs or UPI credentials touch our servers
- Payment links are single-purpose and expire
- Webhooks are signature-verified before we trust a single rupee
- Every payment and refund is written to the audit log
Where we are on formal certification
We are a young company and we would rather tell you this plainly than imply otherwise: VaidyaX is not yet independently certified against ISO 27001 or SOC 2. The controls on this page are real and in place today, and formal certification is on our roadmap as we grow. Our payment processing runs on a PCI-DSS certified provider.
If your organisation needs a security questionnaire completed before you can sign, send it over — we answer them ourselves, honestly, including the parts where the answer is “not yet”.
What we do, and what only you can do
Most breaches at small practices are not sophisticated attacks. They are a shared login and a staff member who left in March.
We handle
- Keeping the platform patched, monitored and available
- Encrypting data in transit and at rest
- Enforcing clinic isolation on every request
- Running and testing daily backups
- Recording an audit trail you can read
- Telling you promptly if something goes wrong
Your clinic handles
- Giving each staff member their own login — never a shared one
- Choosing roles that match what each person actually needs
- Turning on two-factor login for owner and admin accounts
- Removing access the day somebody leaves your clinic
- Keeping patient consent and clinical practice compliant with your local rules
- Using a device and network you trust at the front desk
Responsible disclosure
Found something? Tell us before you tell anyone else.
If you believe you have found a vulnerability, email us with enough detail to reproduce it. We will confirm receipt within two working days, keep you updated while we fix it, and credit you if you would like to be credited. We will not take legal action against good-faith research that avoids patient data and does not degrade the service for clinics.
Please do not test against a live clinic’s account or real patient records.
Questions your compliance team wants answered?
Send them over. We answer security questionnaires ourselves — usually within a couple of days.
- Personalised walkthrough
- No setup fee
- Cancel anytime
