Home/Security & Compliance

    Security & Compliance

    Security and Compliance, Stated Plainly

    Real technical controls — role-based access, per-clinic data isolation, encrypted backups, incident tracking, and signed consent capture — described accurately, including where we currently fall short of a formal certification.

    What We're Not Claiming

    • • Not ISO 27001 certified by an accredited third-party auditor today.
    • • Not currently integrated with ABDM / ABHA (India's Ayushman Bharat Digital Mission).
    • • Not asserting a legal conclusion of full DPDP Act compliance on this page — that's a legal determination, not a marketing claim.

    We'd rather list what we don't have than let silence imply we do. What follows is what's actually built.

    What's Actually Built

    Role-based access control

    Every user has a role — admin, doctor, consulting doctor, consultant, receptionist, finance, or nurse — that determines what they can see and edit. Financial data is explicitly restricted from non-finance roles.

    Multi-clinic data isolation

    Every record — patient, appointment, bill, chart — is scoped to the clinic it belongs to. One clinic's data isn't visible to another unless a user is explicitly granted access to both.

    Encrypted, checksummed backups

    Backups are AES-256 encrypted with a SHA-256 checksum for integrity, retained on a defined schedule, and their restorability is periodically tested rather than assumed.

    Security incident tracking

    Incidents are logged with a type, severity, status, and resolution — from detection through to resolution and preventive measures — not handled informally over chat.

    Consent capture with signatures

    Patient consent for treatments and for consultation recording is captured through versioned templates, signed by patient, guardian, witness, and doctor as applicable, stored as a permanent signed record.

    Security policy tracking

    Password, access, and data-retention policy enforcement is logged, so policy compliance is auditable rather than assumed.

    Evaluating Dantara for Your Institution

    If your clinic, chain, or institution has a specific compliance checklist — a security questionnaire, a data-processing agreement, a certification requirement — send it to us directly rather than relying on this page alone. We'll give you an accurate, current answer, including where we don't yet meet a requirement.

    Contact us with your requirements →

    Have a Security Question?

    Talk to our team directly — we'd rather answer accurately than have you guess from marketing copy.

    Frequently Asked Questions

    Is Dantara ISO 27001 certified?
    No. Dantara is not currently ISO 27001 certified by an accredited third-party auditor. We'd rather say that plainly than let a badge or a claim on this page imply otherwise — if formal certification matters for your procurement process, ask us directly about current status.
    Does Dantara support ABDM / ABHA integration?
    Not currently. If linking to India's Ayushman Bharat Digital Mission is a hard requirement for your clinic today, Dantara isn't yet the right fit for that specific need.
    Is Dantara DPDP Act compliant?
    We've built real technical controls — encryption, access control, consent capture, incident tracking — that support data-protection obligations, but we're not asserting formal DPDP compliance as a legal conclusion on this page. If compliance sign-off is part of your evaluation, raise it directly with our team so we can give you an accurate, current answer rather than marketing copy.
    Are backups encrypted?
    Yes — backups are encrypted (AES-256) with a checksum for integrity verification, retained on a defined schedule, and periodically tested by actually restoring them, not just assumed to work.
    How is patient consent for treatment and recording captured?
    Through versioned consent templates (per treatment type, plus recording consent) that can be signed by the patient, a guardian, a witness, and the doctor, and stored as a signed record with a generated PDF — not a verbal or unrecorded process.
    Who can see what inside Dantara?
    Access follows each user's role — admin, doctor, consulting doctor, consultant, receptionist, finance, or nurse — so, for example, financial data is restricted from non-finance roles and clinical data is scoped to clinical roles.