Security you can explain to a patient in one sentence, and to an auditor in one page.
Patient data is encrypted in transit and at rest, seen only by the roles that need it, logged every time it is touched, and backed up so it can be restored. Here is the detail behind each of those claims.
- Encrypted at rest
- Role-based access
- Audit trail
The law says 'reasonable security safeguards'. A clinic needs something more concrete than that.
The DPDP Act 2023 requires a data fiduciary to protect personal data with reasonable security safeguards and to prevent breaches. The IT Act 2000 and its rules have asked for reasonable security practices since long before that. Neither hands a clinic a checklist. So here is ours, in the order an auditor would ask.
Where does data sit and who can reach it? How is it protected in storage and on the wire? Who inside the clinic can see what? What record exists of every access? What happens if a disk fails, a laptop is stolen, or a staff member leaves? And what independent evidence exists that any of this is true?
Saaro answers the first five with product controls described on this page. The sixth, independent certification, is where we tell you exactly where we stand rather than implying something: certification status.
Security is shared. Here is the split.
Product means Lumotis operates it. Clinic means only you can do it. Both means the product provides the control and the clinic has to use it.
- Saaro handles it
Encrypt data in transit
Every connection between your browser or phone and Saaro, and between Saaro and its sub-processors, uses TLS. There is no unencrypted path.
- Saaro handles it
Encrypt data at rest
Databases, file storage for reports and images, and backups are encrypted at rest with keys managed by the hosting provider's key service and rotated on a schedule.
- Saaro handles it
Separate clinics from each other
Each clinic's data is logically isolated in the platform. A user from one clinic cannot address another clinic's records, and this is enforced in the data layer, not only in the interface.
- Your clinic
Give each staff member their own login
Shared logins defeat the audit trail. Saaro supports unlimited staff users per clinic so a receptionist, nurse and doctor each sign in as themselves.
- Shared
Assign roles that match the job
Front desk, doctor, pharmacy, lab, accounts and owner roles ship with sensible defaults. The owner decides who gets which; the product enforces it.
- Shared
Remove access when someone leaves
Deactivating a user takes one action and ends every session immediately. Doing it on the day they leave is the clinic's job.
- Saaro handles it
Keep an audit trail
Every login, record view, edit, export, message and ABDM transaction is logged with user, timestamp and what changed. Logs cannot be edited from the interface.
- Saaro handles it
Back up and test restores
Backups run on a schedule of backup frequency and are stored encrypted in a separate location in India. Restores are tested on a schedule of restore test cadence.
- Your clinic
Protect the devices you use
A stolen unlocked phone with Saaro open is a breach. Screen locks, not sharing devices, and signing out on shared counters are clinic behaviours the product cannot replace.
- Saaro handles it
Test the platform independently
External penetration testing is carried out on a cadence of pen test cadence. Findings are fixed and a summary is available to customers on request.
The controls, as they appear in the product.
Roles and permissions
Six built-in roles cover an Indian OPD. Owners can restrict clinical notes to doctors, billing to accounts, and dispensing to pharmacy, per branch.
Learn moreAudit log per patient
Open any record and see who viewed, edited, exported or messaged it, and when. The same log is exportable for the whole clinic for an auditor.
Learn moreSession and device control
Owners can see active sessions, sign a device out remotely, and require re-login after a set idle time on shared counter machines.
Messaging on owned infrastructure
WhatsApp messages go through SaroConnect, Lumotis's own WhatsApp Business Solution Provider infrastructure. No third-party BSP holds your patients' numbers or message content.
Learn moreExport under control
Bulk export is an owner-only action, logged, and delivered as an encrypted archive. Individual patient exports are logged against the record.
Hosted in India
All patient data is stored and processed in hosting region. The full sub-processor list is published and change-notified.
Learn more
The audit trail is a timeline, not a log file.
A patient asks who has seen their file. An owner wants to know who exported the diabetic list last Tuesday. An auditor wants proof that a departed receptionist's access ended on their last day. All three are answered from the same screen.
Entries cannot be edited or deleted from the interface, including by the owner. That is the point of them.
- User, role, time and action on every entry
- Views logged, not only edits
- Exports and messages included
- Clinic-wide export for auditors
- 09:12Record viewed · Reception (Sunita)View
- 09:40Notes edited · Dr RaoEdit
- 09:41Rx #4830 sent on WhatsApp · Dr RaoMessage
- Tue 2 SepRecord exported at patient's request · OwnerExport
The question an auditor asks, and the answer.
Values in braces are confirmed during onboarding and in the data processing agreement. Certification status: certification status.
| Question | Saaro answer | Evidence available |
|---|---|---|
| Where is data stored? | India, hosting region | Sub-processor list; data processing agreement |
| Is data encrypted in transit? | Yes, TLS on every connection | Configuration summary on request |
| Is data encrypted at rest? | Yes, databases, files and backups | Configuration summary on request |
| Who can see clinical notes? | Roles the owner assigns; default doctors only | Role matrix in the workspace settings |
| Is every access logged? | Yes, views, edits, exports, messages | Per-patient and clinic-wide audit export |
| Can logs be altered? | Not from the interface, by any role | Audit design note on request |
| How often are backups taken? | backup frequency | Backup and restore policy |
| Are restores tested? | Yes, on a cadence of restore test cadence | Restore test record on request |
| Is the platform tested externally? | Yes, on a cadence of pen test cadence | Summary letter on request |
| Is there an independent certification? | certification status | Certificate or roadmap on request |
| Who handles WhatsApp traffic? | SaroConnect, owned by Lumotis | Sub-processor list |
| What happens on a breach? | Clinic notified without undue delay with details | Data processing agreement, breach clause |
Swipe to see every tier
Your questions answered.
The things clinics ask first.
Yes. In transit, every connection uses TLS. At rest, databases, report files and backups are encrypted with keys managed by the hosting provider's key service. There is no unencrypted copy.
Only if you give the front desk role that permission. By default the reception role can register, book, bill and message but not open clinical notes or prescriptions.
Yes. Every view, edit, export, message and ABDM event is logged with user, time and what changed, per patient and clinic-wide. Entries cannot be edited from the interface.
Our current status is {{CERTIFICATION_STATUS}}. We would rather state that plainly than imply a certification we do not hold. Ask on the demo call for the latest position.
Sign the device out remotely from the owner's session list, and every session on it ends. The audit trail shows any access that happened in between, so you know what to report if anything.
Backups are encrypted and stored in a separate location in India. Independently of backups, an owner can export the clinic's complete data at any time as an encrypted archive.
Keep reading.
- FeaturesPatient recordsA record built from every visit, not a spreadsheet row. Prescriptions, reports, notes and follow-ups sit in one timeline, linked to the patient's ABHA if they have one.
- FeaturesMulti-clinicSaaro runs a clinic chain as one system: a shared patient index, doctors who move between branches, billing that stays separate per location, and a single view for the owner.
- FeaturesWhatsApp automationSaaro runs on SaroConnect, Lumotis's own WhatsApp Business infrastructure. Reminders, prescriptions, reports and refills go out from your number, patient replies come back to the desk, and messaging is included in every plan.
- TrustData residencySaaro Health is hosted in India, in hosting region. Databases, report files, backups and the WhatsApp messaging layer are all in-country. The one thing that crosses a border is the WhatsApp message itself, and we say so.
- TrustDPDP complianceConsent, notice, retention, erasure, breach reporting and grievance handling are obligations on the clinic. Here is what each one means for an OPD, and which parts the product does for you.
- TrustSub-processorsA sub-processor is any company Lumotis uses to process clinic data on your behalf. This page lists them, says what each does and where it runs, and explains how you are told before one is added.
Ask the hard questions on a call.
Bring your auditor's checklist. We will answer each item and show the screen behind it.
