Skip to main content

Security

Security and privacy are built into the foundation.

Healthcare data deserves careful handling. Medyntra is designed with tenant isolation, role-based access, auditability and secure data handling at its core.

  1. Verified session
  2. Active membership
  3. Database policy

Every request passes three independent checks before data is returned.

How we protect data

Controls you can explain to your board.

Data isolation

Each hospital is a separate tenant. Its data is logically isolated from every other organization’s.

  • The organization is derived from your signed-in session and membership — never from what a browser sends
  • Database row-level policies return nothing outside the organization in context
  • Automated tests attempt cross-organization access on every change

Role-based access

Users only receive access appropriate to their assigned permissions.

  • Granular permissions per action, such as billing.refund
  • Checked on the server for every request
  • Nobody can grant permissions they do not hold themselves

Encryption

Data is encrypted in transit and stored with encryption at rest provided by the managed database and object-storage services the platform runs on.

  • HTTPS with HSTS for every connection
  • Object storage with server-side encryption and public access blocked
  • Provider credentials kept in secret stores, never in the browser

Secure authentication

Accounts use verified email addresses, strong password hashing and server-side sessions.

  • Sessions can be reviewed and signed out from any device
  • Password resets sign out every other session
  • Sign-in attempts are rate limited

Audit logs

Important actions are recorded for accountability and traceability.

  • Sign-ins, permission changes and administrative actions
  • Append-only: records cannot be edited or deleted by the application
  • Visible to authorized administrators

Private documents

Files are stored in private object storage and accessed through controlled mechanisms.

  • No public links to stored files
  • Uploads checked by file type and size
  • Served only to permitted users

Infrastructure

The platform is designed to run on managed cloud services in India, with separate environments for development, staging and production.

  • Managed PostgreSQL and object storage, India region preferred
  • Security headers and strict configuration validation
  • Secrets stored in the hosting platform’s secret stores

Backups & recovery

The backup strategy combines the database provider’s point-in-time recovery with nightly encrypted logical backups stored separately, with periodic restore tests.

  • Point-in-time recovery for the production database
  • Encrypted backups kept in a separate location
  • Recovery objectives agreed in customer contracts

AI security

AI features are designed to stay within the same boundaries as the rest of the platform.

  • AI does not receive unrestricted database access
  • AI operates through permission-controlled tools and respects tenant boundaries
  • Responses are generated from authorized data, and AI is not a substitute for clinical judgment

Data privacy

Your data belongs to you.

We handle hospital and patient data according to the platform’s policies and our contractual commitments.

  • Hospital data is tenant-specific
  • Patient data is never used as generic public content
  • Access is permission-controlled
  • Sensitive actions are auditable
Read the Privacy Policy

Trust

Built for sensitive healthcare workflows.

  • Tenant isolation

    Each organization’s data kept separate.

  • Role-based access

    Access matched to each role.

  • Audit trails

    Important actions recorded.

  • Secure documents

    Private storage, controlled access.

  • Controlled AI access

    Permission-checked, tenant-bound AI.

  • Protected infrastructure

    Managed services, encrypted transport.

FAQ

Common questions

Is each hospital's data kept separate?

Yes. Every hospital is an isolated tenant: access is checked on the server for every request and enforced again inside the database with row-level security.

Who can access what?

Access is role-based with granular permissions — the interface only hides what the server already refuses. Important actions are written to an audit log that can't be edited.

How are sign-ins protected?

Passwords are hashed, sessions are kept on the server and can be revoked immediately, and platform staff use two-factor authentication.

Have questions about how Medyntra handles your organization’s data?

Our team can walk you through tenant isolation, access controls, auditability and our data-handling practices.