Launch offer: First 50 clinics get 50 % off for 12 months. Claim your spot →

Security & compliance

Patient data is the most sensitive thing your practice handles. Medixar is engineered with that in mind — tenant isolation in the database, encryption end-to-end, append-only audit, and a documented incident plan.

This page describes the controls Medixar has in production today. We update it as our security posture evolves. For the formal contractual document, customers can request our security questionnaire, BAA (Business Associate Agreement), or DPA (Data Processing Addendum) by writing to security@medixar.ai.

1. Architecture

Tenant isolation

Every clinic, hospital, or chain that signs up gets its own logical tenant. Inside our shared PostgreSQL cluster, each row in every business table carries a tenant_id column, and every row is protected by PostgreSQL row-level security policies. The application layer cannot, by construction, ever return data belonging to another tenant — even a logic bug in our code is caught by the database before the row leaves the server.

Cross-tenant queries (used only for our own platform admin dashboards) run on a separate superuser connection and are explicitly audited.

Encryption

Authentication & authorisation

2. Audit & observability

3. Data residency

Production data for Indian customers is hosted in AWS Mumbai (ap-south-1). Daily encrypted backups remain in the same region. Sub-processors that operate outside India (Anthropic for AI inference, Stripe for international payments) are governed by Standard Contractual Clauses; PHI sent to AI providers is processed transiently and is contractually excluded from training their models.

4. Compliance posture

FrameworkStatusNotes
HIPAA (USA) Aligned BAA available on request. Audit log + encryption + access control satisfy §164.312.
ABDM / Ayushman Bharat Digital Mission (India) Ready ABHA verification, Health Information Exchange callback infrastructure, consent artefact handling.
DPDPA 2023 (India) Aligned Data principal rights handled via privacy@medixar.ai; clinics act as data fiduciaries for patient data.
IT Act 2000 + SPDI Rules 2011 (India) Compliant Reasonable security practices, breach notification process, grievance officer designated.
NABH Digital Standards Ready Digital signature support, ABHA integration, audit log retention, configurable record retention.
SOC 2 Type II Roadmap We expect to begin a SOC 2 Type II observation window in 2026.

5. Vulnerability management & testing

6. Incident response

7. Personnel security

8. Business continuity

9. Sub-processors

The current list of sub-processors is published on our privacy policy and updated when it changes. Customers can subscribe to advance notice of sub-processor changes by writing to security@medixar.ai.

10. Documents available on request

Email security@medixar.ai to request any of the above or to schedule a security review with the founding team.