Clinic-scoped access
Every production data entity is designed around clinic boundaries and role-based access.
Trust
The platform is designed for clinic-scoped data, masked identity handling, server-side secrets, audit events, and signed webhook integrations.

Security decisions are visible in product behavior, not hidden in policy text.
Every production data entity is designed around clinic boundaries and role-based access.
Raw Aadhaar numbers are not displayed; storage paths use hashing, masking, and audit sanitization.
State-changing workflows log audit events so clinic owners can review sensitive operational changes.
Payment, WhatsApp, and database credentials stay on the server side with webhook signature checks.