Enterprise-grade security.
Healthcare-grade compliance.
Your patients trust you with their health data. We treat that responsibility as sacred. Every design decision starts with security, not features.
256-bit
AES encryption
99.99%
Uptime SLA
Daily
Encrypted backups
SOC 2
Independently audited
Certifications and Compliance
Healthcare has the strictest data protection requirements of any industry. We meet all of them.
DPDP Act 2023
Full compliance with India's Digital Personal Data Protection Act. Data localization, consent management, and purpose limitation enforced at every layer.
HIPAA Ready
Technical safeguards meeting US healthcare data protection requirements. BAA available for cross-border partnerships and NRI clinics.
SOC 2 Type II
Independently audited controls for security, availability, and confidentiality. Annual audit by certified third-party firms.
GDPR Compliant
European data protection standards met for global operations. Right to erasure, data portability, and lawful processing basis documented.
ISO 27001 Aligned
Information security management following international standards. Risk assessment, asset inventory, and incident response procedures formalized.
ABDM Compliant
Registered with India's Ayushman Bharat Digital Mission health stack. ABHA ID integration, health record exchange, and consent framework supported.

Enterprise-grade infrastructure
Built on the same cloud infrastructure trusted by India's largest hospitals and health systems. Redundant, resilient, and designed to never go down.
- Multi-availability-zone deployment
- Automated failover with zero data loss
- 24/7 infrastructure monitoring
- India-only data residency guaranteed
Data Flow Architecture
Every data transmission is encrypted end-to-end. No plaintext data ever travels across the network.
Client Device
Mobile / Desktop
TLS 1.3
Relaya Cloud
Processing Layer
AES-256
Encrypted Database
India-hosted
All data encrypted at rest and in transit. Patient records never leave Indian borders.
Infrastructure Security
Defense in depth. Every layer protected independently so a single failure never exposes patient data.
Data Centers
- Primary: AWS Mumbai (ap-south-1), Tier III+ facility
- Disaster recovery: AWS Hyderabad (ap-south-2)
- All patient data remains exclusively within Indian borders
- Physical security: biometric access, 24/7 surveillance, mantraps
- SOC 2 and ISO 27001 certified facilities
Encryption Standards
- Data at rest: AES-256-GCM encryption on all storage volumes
- Data in transit: TLS 1.3 with perfect forward secrecy
- Database: column-level encryption for sensitive fields (PII, PHI)
- Audio recordings: encrypted from device to storage, key rotation every 90 days
- Backup encryption: separate key hierarchy from production
Access Controls
- Role-based access control (RBAC) with principle of least privilege
- Multi-factor authentication required for all team members
- Session tokens: short-lived (15 min) with secure refresh rotation
- API keys: scoped per-resource, revocable, with usage audit trails
- No standing admin access; just-in-time elevation with approval workflow
Audit Logging
- Every data access logged with who, what, when, and from where
- Immutable audit trail; logs cannot be modified or deleted
- Retention: 7 years for compliance, 90 days hot storage for investigation
- Automated anomaly detection on access patterns
- Quarterly access reviews with automatic deprovisioning
Operational Security
Security spans infrastructure, process, personnel, and continuous monitoring. Every layer audited independently.
Vulnerability Management
Automated dependency scanning on every build. Annual third-party penetration testing by certified firms. Critical vulnerabilities patched within 24 hours. Bug bounty program for responsible disclosure.
Incident Response
30-minute SLA for critical security incidents. Documented runbooks for every threat scenario. Post-incident reviews published within 72 hours. Customers notified within 4 hours of any data breach.
Backup and Recovery
Point-in-time recovery with 5-minute RPO. Automated daily backups with cross-region replication. Quarterly disaster recovery drills. RTO under 4 hours for full system restoration.
Personnel Security
Background checks for all team members with data access. Security awareness training quarterly. Signed confidentiality agreements. Immediate access revocation upon role change or departure.
Network Security
Web application firewall (WAF) on all public endpoints. DDoS mitigation with automatic traffic scrubbing. Private subnets for all application and database layers. No direct internet access to production databases.
Compliance Monitoring
Continuous compliance monitoring against DPDP, HIPAA, and SOC 2 controls. Automated evidence collection for audit readiness. Annual external audits with reports available to customers under NDA.
Data Handling Principles
Data Minimization
We collect only what is necessary for the service to function. No behavioral tracking. No data selling. No advertising profiles. Your patient data exists for one purpose: serving your patients.
Data Portability
Your data belongs to you. Export everything at any time in standard formats (FHIR R4, CSV, JSON). No lock-in. No exit fees. No data hostage situations.
Data Deletion
Request deletion and we purge all patient data within 30 days, including backups. Verified deletion with certificate of destruction provided on request.
Zero-Knowledge Architecture
Relaya staff cannot access your clinical notes without explicit, time-limited permission. All access requires documented justification, manager approval, and creates an immutable audit record.
Tenant Isolation
Multi-tenant architecture with strict logical isolation. Each clinic's data is separated at the database level. No clinic can ever access another clinic's records, even through application bugs.
AI Model Privacy
Voice AI and clinical scribe process data in real-time and do not retain conversation content after processing. No patient data is used to train general-purpose AI models. Ever.
Responsible Disclosure
Found a vulnerability? We appreciate responsible disclosure and respond to all valid reports within 24 hours. Critical issues receive acknowledgment within 4 hours.
security@relaya.oneSecurity Documentation Available Under NDA
SOC 2 reports, penetration test summaries, and full security documentation are available to customers and prospects under NDA. Contact our team to request access.
Request security review