Data & privacy

Patient data is a trust, not an asset.

Health records are among the most sensitive data an Indian business can hold. This page says plainly how Agnivesha handles them — including what we don't claim yet.

A database per institution

Every institution runs in its own isolated database — your records never share a schema, a table, or a query with another tenant.

🔐

Role-based access

A curated role catalog decides who sees what, down to the screen and action. Panel access, permissions and role handbooks are generated from one live matrix.

📜

Audit trails

Clinical and financial actions are logged — who did what, when, to which record — across workspaces.

🔑

Secrets encrypted at rest

Institution-level credentials and API secrets are stored encrypted, not in plain text.

🤖

AI on a leash

Every AI call is PII-scrubbed before it leaves, metered against a per-institution budget, and logged for audit. Clinical decisions stay with clinicians — always.

🚫

No data monetisation

We don't sell, mine, or advertise against patient data. Your records exist to serve your patients, full stop.

What we don't claim yet.

Trust pages that only list strengths aren't trust pages. Here is the honest state of the things buyers usually ask about — the same transparency notes we keep in our feature books.

Ask us anything →
ABDM / ABHA. The integration surface is built and ABHA-ready; production ABDM keys are in progress — we say "ready", not "certified".
DPDP Act. Isolation, access control and audit are designed around its principles; we do not claim a formal certification.
App stores. Mobile apps ship as white-label builds distributed directly; public store listings are roadmap.
When this page changes. As items above land, this list shrinks — check What's New for dates.

Questions about data handling?

Write to us and we'll answer in plain language, in writing.

Email the team →