New: Voice AI now handles 47+ calls daily per clinic. See how it works
Security and Compliance

Enterprise-grade security.
Healthcare-grade compliance.

Your patients trust you with their health data. We treat that responsibility as sacred. Every design decision starts with security, not features.

256-bit

AES encryption

99.99%

Uptime SLA

Daily

Encrypted backups

SOC 2

Independently audited

Certifications and Compliance

Healthcare has the strictest data protection requirements of any industry. We meet all of them.

DPDP Act 2023

Full compliance with India's Digital Personal Data Protection Act. Data localization, consent management, and purpose limitation enforced at every layer.

HIPAA Ready

Technical safeguards meeting US healthcare data protection requirements. BAA available for cross-border partnerships and NRI clinics.

SOC 2 Type II

Independently audited controls for security, availability, and confidentiality. Annual audit by certified third-party firms.

GDPR Compliant

European data protection standards met for global operations. Right to erasure, data portability, and lawful processing basis documented.

ISO 27001 Aligned

Information security management following international standards. Risk assessment, asset inventory, and incident response procedures formalized.

ABDM Compliant

Registered with India's Ayushman Bharat Digital Mission health stack. ABHA ID integration, health record exchange, and consent framework supported.

Modern hospital infrastructure

Enterprise-grade infrastructure

Built on the same cloud infrastructure trusted by India's largest hospitals and health systems. Redundant, resilient, and designed to never go down.

  • Multi-availability-zone deployment
  • Automated failover with zero data loss
  • 24/7 infrastructure monitoring
  • India-only data residency guaranteed

Data Flow Architecture

Every data transmission is encrypted end-to-end. No plaintext data ever travels across the network.

Client Device

Mobile / Desktop

TLS 1.3

Relaya Cloud

Processing Layer

AES-256

Encrypted Database

India-hosted

All data encrypted at rest and in transit. Patient records never leave Indian borders.

Infrastructure Security

Defense in depth. Every layer protected independently so a single failure never exposes patient data.

Data Centers

  • Primary: AWS Mumbai (ap-south-1), Tier III+ facility
  • Disaster recovery: AWS Hyderabad (ap-south-2)
  • All patient data remains exclusively within Indian borders
  • Physical security: biometric access, 24/7 surveillance, mantraps
  • SOC 2 and ISO 27001 certified facilities

Encryption Standards

  • Data at rest: AES-256-GCM encryption on all storage volumes
  • Data in transit: TLS 1.3 with perfect forward secrecy
  • Database: column-level encryption for sensitive fields (PII, PHI)
  • Audio recordings: encrypted from device to storage, key rotation every 90 days
  • Backup encryption: separate key hierarchy from production

Access Controls

  • Role-based access control (RBAC) with principle of least privilege
  • Multi-factor authentication required for all team members
  • Session tokens: short-lived (15 min) with secure refresh rotation
  • API keys: scoped per-resource, revocable, with usage audit trails
  • No standing admin access; just-in-time elevation with approval workflow

Audit Logging

  • Every data access logged with who, what, when, and from where
  • Immutable audit trail; logs cannot be modified or deleted
  • Retention: 7 years for compliance, 90 days hot storage for investigation
  • Automated anomaly detection on access patterns
  • Quarterly access reviews with automatic deprovisioning

Operational Security

Security spans infrastructure, process, personnel, and continuous monitoring. Every layer audited independently.

Vulnerability Management

Automated dependency scanning on every build. Annual third-party penetration testing by certified firms. Critical vulnerabilities patched within 24 hours. Bug bounty program for responsible disclosure.

Incident Response

30-minute SLA for critical security incidents. Documented runbooks for every threat scenario. Post-incident reviews published within 72 hours. Customers notified within 4 hours of any data breach.

Backup and Recovery

Point-in-time recovery with 5-minute RPO. Automated daily backups with cross-region replication. Quarterly disaster recovery drills. RTO under 4 hours for full system restoration.

Personnel Security

Background checks for all team members with data access. Security awareness training quarterly. Signed confidentiality agreements. Immediate access revocation upon role change or departure.

Network Security

Web application firewall (WAF) on all public endpoints. DDoS mitigation with automatic traffic scrubbing. Private subnets for all application and database layers. No direct internet access to production databases.

Compliance Monitoring

Continuous compliance monitoring against DPDP, HIPAA, and SOC 2 controls. Automated evidence collection for audit readiness. Annual external audits with reports available to customers under NDA.

Data Handling Principles

Data Minimization

We collect only what is necessary for the service to function. No behavioral tracking. No data selling. No advertising profiles. Your patient data exists for one purpose: serving your patients.

Data Portability

Your data belongs to you. Export everything at any time in standard formats (FHIR R4, CSV, JSON). No lock-in. No exit fees. No data hostage situations.

Data Deletion

Request deletion and we purge all patient data within 30 days, including backups. Verified deletion with certificate of destruction provided on request.

Zero-Knowledge Architecture

Relaya staff cannot access your clinical notes without explicit, time-limited permission. All access requires documented justification, manager approval, and creates an immutable audit record.

Tenant Isolation

Multi-tenant architecture with strict logical isolation. Each clinic's data is separated at the database level. No clinic can ever access another clinic's records, even through application bugs.

AI Model Privacy

Voice AI and clinical scribe process data in real-time and do not retain conversation content after processing. No patient data is used to train general-purpose AI models. Ever.

Responsible Disclosure

Found a vulnerability? We appreciate responsible disclosure and respond to all valid reports within 24 hours. Critical issues receive acknowledgment within 4 hours.

security@relaya.one

Security Documentation Available Under NDA

SOC 2 reports, penetration test summaries, and full security documentation are available to customers and prospects under NDA. Contact our team to request access.

Request security review
Chat with us on WhatsApp