Skip to content
Saaro Health
Trust

Security you can explain to a patient in one sentence, and to an auditor in one page.

Patient data is encrypted in transit and at rest, seen only by the roles that need it, logged every time it is touched, and backed up so it can be restored. Here is the detail behind each of those claims.

  • Encrypted at rest
  • Role-based access
  • Audit trail
What is expected

The law says 'reasonable security safeguards'. A clinic needs something more concrete than that.

The DPDP Act 2023 requires a data fiduciary to protect personal data with reasonable security safeguards and to prevent breaches. The IT Act 2000 and its rules have asked for reasonable security practices since long before that. Neither hands a clinic a checklist. So here is ours, in the order an auditor would ask.

Where does data sit and who can reach it? How is it protected in storage and on the wire? Who inside the clinic can see what? What record exists of every access? What happens if a disk fails, a laptop is stolen, or a staff member leaves? And what independent evidence exists that any of this is true?

Saaro answers the first five with product controls described on this page. The sixth, independent certification, is where we tell you exactly where we stand rather than implying something: certification status.

Responsibilities

Security is shared. Here is the split.

Product means Lumotis operates it. Clinic means only you can do it. Both means the product provides the control and the clinic has to use it.

  1. Encrypt data in transit

    Every connection between your browser or phone and Saaro, and between Saaro and its sub-processors, uses TLS. There is no unencrypted path.

    Saaro handles it
  2. Encrypt data at rest

    Databases, file storage for reports and images, and backups are encrypted at rest with keys managed by the hosting provider's key service and rotated on a schedule.

    Saaro handles it
  3. Separate clinics from each other

    Each clinic's data is logically isolated in the platform. A user from one clinic cannot address another clinic's records, and this is enforced in the data layer, not only in the interface.

    Saaro handles it
  4. Give each staff member their own login

    Shared logins defeat the audit trail. Saaro supports unlimited staff users per clinic so a receptionist, nurse and doctor each sign in as themselves.

    Your clinic
  5. Assign roles that match the job

    Front desk, doctor, pharmacy, lab, accounts and owner roles ship with sensible defaults. The owner decides who gets which; the product enforces it.

    Shared
  6. Remove access when someone leaves

    Deactivating a user takes one action and ends every session immediately. Doing it on the day they leave is the clinic's job.

    Shared
  7. Keep an audit trail

    Every login, record view, edit, export, message and ABDM transaction is logged with user, timestamp and what changed. Logs cannot be edited from the interface.

    Saaro handles it
  8. Back up and test restores

    Backups run on a schedule of backup frequency and are stored encrypted in a separate location in India. Restores are tested on a schedule of restore test cadence.

    Saaro handles it
  9. Protect the devices you use

    A stolen unlocked phone with Saaro open is a breach. Screen locks, not sharing devices, and signing out on shared counters are clinic behaviours the product cannot replace.

    Your clinic
  10. Test the platform independently

    External penetration testing is carried out on a cadence of pen test cadence. Findings are fixed and a summary is available to customers on request.

    Saaro handles it
In the record

The audit trail is a timeline, not a log file.

A patient asks who has seen their file. An owner wants to know who exported the diabetic list last Tuesday. An auditor wants proof that a departed receptionist's access ended on their last day. All three are answered from the same screen.

Entries cannot be edited or deleted from the interface, including by the owner. That is the point of them.

  • User, role, time and action on every entry
  • Views logged, not only edits
  • Exports and messages included
  • Clinic-wide export for auditors
AAnita M.41 · F · Audit trail
  • 09:12Record viewed · Reception (Sunita)View
  • 09:40Notes edited · Dr RaoEdit
  • 09:41Rx #4830 sent on WhatsApp · Dr RaoMessage
  • Tue 2 SepRecord exported at patient's request · OwnerExport
Mapping

The question an auditor asks, and the answer.

Values in braces are confirmed during onboarding and in the data processing agreement. Certification status: certification status.

QuestionSaaro answerEvidence available
Where is data stored?India, hosting regionSub-processor list; data processing agreement
Is data encrypted in transit?Yes, TLS on every connectionConfiguration summary on request
Is data encrypted at rest?Yes, databases, files and backupsConfiguration summary on request
Who can see clinical notes?Roles the owner assigns; default doctors onlyRole matrix in the workspace settings
Is every access logged?Yes, views, edits, exports, messagesPer-patient and clinic-wide audit export
Can logs be altered?Not from the interface, by any roleAudit design note on request
How often are backups taken?backup frequencyBackup and restore policy
Are restores tested?Yes, on a cadence of restore test cadenceRestore test record on request
Is the platform tested externally?Yes, on a cadence of pen test cadenceSummary letter on request
Is there an independent certification?certification statusCertificate or roadmap on request
Who handles WhatsApp traffic?SaroConnect, owned by LumotisSub-processor list
What happens on a breach?Clinic notified without undue delay with detailsData processing agreement, breach clause

Swipe to see every tier

Your questions answered.

The things clinics ask first.

Yes. In transit, every connection uses TLS. At rest, databases, report files and backups are encrypted with keys managed by the hosting provider's key service. There is no unencrypted copy.

Only if you give the front desk role that permission. By default the reception role can register, book, bill and message but not open clinical notes or prescriptions.

Yes. Every view, edit, export, message and ABDM event is logged with user, time and what changed, per patient and clinic-wide. Entries cannot be edited from the interface.

Our current status is {{CERTIFICATION_STATUS}}. We would rather state that plainly than imply a certification we do not hold. Ask on the demo call for the latest position.

Sign the device out remotely from the owner's session list, and every session on it ends. The audit trail shows any access that happened in between, so you know what to report if anything.

Backups are encrypted and stored in a separate location in India. Independently of backups, an owner can export the clinic's complete data at any time as an encrypted archive.

Related

Keep reading.

Ask the hard questions on a call.

Bring your auditor's checklist. We will answer each item and show the screen behind it.