Compliance
What we claim, and what we refuse to.
Most vendor compliance pages are a wall of logos. This one is a list of what we can evidence and a longer list of what we will not assert, which is more useful to a compliance team and considerably more awkward to write.
Where we actually stand
Four areas, each with the state written plainly rather than as a badge.
ABDM
Built, sandbox-verified, not certifiedMilestones 1 to 4 are implemented and verified in the National Health Authority sandbox. No health record has been exchanged in production, in either direction, in any environment. Going live requires NHA functional testing, a security audit certificate and Health Tech Committee approval, and we hold none of the three.
DPDP Act 2023
Designed for, not certifiedDatabase-enforced tenant isolation, role-based access with per-user overrides, an append-only audit trail, encryption in transit and at rest, India-resident storage, and a published sub-processor list. A patient-facing rights workflow and a purpose-scoped consent registry are scheduled rather than built.
NABH
We support your evidence; we are not accreditedAccreditation is granted to a hospital, never to software. We contribute structured clinical documentation, an audit trail, access control and electronic signatures. We have no medication safety checking and no quality-indicator engine; the inpatient module is built and in verification but not yet running in a customer’s hospital, so it is not yet a source of live evidence for the ward standards.
GST and e-invoicing
Partially builtInvoice lines carry a tax rate and tax is computed per line; pharmacy items carry HSN/SAC. The CGST/SGST split on the printed invoice and a periodic tax summary are scheduled.
Claims we will not make.
Published so you can hold us to it, and so that a competitor claiming any of these can be asked the same question.
ISO 27001, SOC 2 Type II, HIPAA or GDPR certification
No audit has been performed against any of them. We say “designed for” and “aligned with”, and we will keep saying that until an auditor’s report exists to say otherwise.
ABDM certified, or NHA approved
We have built the milestones and verified them in the sandbox. Certification is a different thing with a document behind it, and we do not have one.
NABH or NABL compliant software
Accreditation belongs to the hospital or the laboratory. Software can support the evidence; it cannot hold the accreditation, and a vendor claiming otherwise is describing something that does not exist.
An uptime percentage
We have no production deployment and therefore nothing measured. A number here would be an aspiration formatted as a fact.
Customer counts, patient volumes or outcome percentages
We have no customers yet. When we do, the numbers will come from our own records, not from a range that sounds plausible.
Integration counts
“200+ integrations” is a promise per device that somebody has to keep. We name the systems we have actually connected to, which today is a short list.
How this is enforced
Not by good intentions. Every capability on this site carries a status that traces to a single file in the codebase, and a capability moves to “built” in the same change that ships it, never ahead of it. A module can be fully written and still be marked planned here, which is exactly the case for our ABDM work.
It costs us comparisons. A buyer scanning two vendor sites will see more badges on the other one. We think the hospitals who notice why are the hospitals worth having.
Questions a compliance team asks
- Are you certified for anything?
- No. Not ABDM, not ISO 27001, not SOC 2, not HIPAA. We are early, and pretending otherwise would be the easiest thing on this website to disprove.
- Then why should a compliance team take you seriously?
- Because the controls are real and inspectable even though no auditor has yet inspected them: isolation enforced by the database, access refused on the server, an append-only audit trail, and a named sub-processor list. Ask us to demonstrate any of it.
- Will you get certified?
- ABDM certification is on the path and gated on functional testing and a security audit. For the broader information-security standards, we would rather be honest about not holding them today than announce a timeline we cannot control.
- How do we assess you without a certificate?
- The way you would assess any early vendor: look at the architecture, ask how isolation is tested, read the sub-processor list, and ask what happens to your data when you leave. Every one of those has an answer on this site.
Bring your compliance team to the demo.
They ask better questions than procurement does, and we would rather answer them early.