arrow_backBack to home

Trust, by architecture

Your patients' records are never the product.

A clinic is handing over the most private records a person has. ClinOps is built so that safety is structural — not a policy page, but the way the system is wired. We never sell, share, or mine patient data. Full stop.

lock
MFA on every session

Two-factor authentication is mandatory on every login — TOTP codes with backup recovery. No exceptions, no shortcut for clinical data.

hub
Strict clinic isolation

Row-level security across 38+ database tables means one clinic can never see another's data. Zero cross-tenant leakage — enforced at the database, not just the app.

encrypted
Encrypted, end to end

AES-256-GCM for sensitive data at rest, TLS in transit. Every uploaded file is verified at the byte level before it is ever stored.

receipt_long
Immutable billing & audit

Payment records can't be quietly edited — immutability is enforced by the database itself. Every PHI access, payment and critical action is written to an audit trail.

dns
Hosted in India

Patient data lives on infrastructure in Mumbai, under Indian law. No patient data leaves the country.

gavel
DPDP 2023, built in

Consent captured at registration. OTP-verified patient data erasure. Per-patient export. The Act's requirements are part of the design, not bolted on.

verified_userDPDP 2023
encryptedAES-256-GCM
dnsHosted in Mumbai
lockMFA every login
history_toggle_offImmutable billing
Full security overview arrow_forward