Security
Patient data,
protected by design.
Health records are among the most sensitive data a clinic holds. DeskMed is built so every clinic’s data stays encrypted, isolated, and in India — with security baked into the architecture, not bolted on.
- Encryption
- AES-256
- Data residency
- India only
- Uptime SLA
- 99.9%
- Compliance
- DPDP-aligned
How we protect you
Security at every layer
From the database to the browser, here’s what keeps your clinic’s data safe.
Encryption everywhere
Traffic is protected with TLS 1.3 in transit and AES-256 at rest. Backups and file attachments — lab reports, scans, documents — are encrypted with the same standard.
Tenant isolation
Every clinic is a separate organization, and every record is scoped to it at the query layer. One clinic can never read or write another clinic's data — it's enforced on every request, not just the UI.
Role-based access
Admins, doctors, receptionists, and lab technicians each see only what their role needs. Least-privilege access keeps prescriptions, billing, and reports in the right hands.
Audited & accountable
Every change to a patient or appointment writes an immutable audit log — who did what, and when. If a record is touched, there's a trail.
Secure authentication
Passwords are hashed with bcrypt and never stored in plain text. Sessions use short-lived access tokens with rotating refresh tokens, so a leaked token expires fast.
Backups & recovery
Encrypted backups run automatically every day with point-in-time recovery. We test restores regularly, so your records are recoverable — not just backed up.
Compliance & residency
Built for Indian healthcare rules
Your data is hosted in India and handled to the standards regulators and patients expect.
DPDP Act 2023
AlignedBuilt to India's Digital Personal Data Protection Act for consent, access, and erasure.
ISO 27001
In progressInformation-security management certification, currently underway.
SOC 2 Type II
On roadmapIndependent audit of our security and availability controls.
HIPAA-aligned
PracticesWe follow HIPAA-style safeguards for handling protected health information.
Data residency
All clinic and patient data is stored and processed on AWS infrastructure in the Mumbai region (ap-south-1). Your records never leave the country.
Found a vulnerability?
We welcome responsible disclosure from security researchers. Report an issue and we’ll acknowledge it within two business days.