Skip to content

Safety & security

Clinical safety, and the protection of patient data

What is in the product as shipped, how each part works, and where each one stops. Every line on this page can be shown to you in the software.

Clinical safety

Checks that inform the clinician, and keep a record

The software warns and records. It does not overrule a clinician: a warning that cannot be overridden gets worked around, and then it protects nobody.

A wristband recording a penicillin allergy, linked to a warning for amoxicillin and a lower-level warning for a cephalosporin.

Allergy checks by drug class

A recorded penicillin allergy warns when amoxicillin is prescribed, because amoxicillin is a penicillin. Cephalosporins warn at a lower level, as a possible cross-reaction.

A tablet and a capsule joined by a warning sign.

Common interactions

Built-in checks for common drug interactions, as a starter set. It can be extended with a licensed drug database if you want fuller coverage.

A warning with a reason typed into it, a Continue button, and a note that the reason was recorded.

Warnings that are answered

Warnings never block. The prescriber types a reason, and it is kept against the prescription for anyone reviewing the case later.

A lab report signed off by two different people, one entering the result and another releasing it.

Two people for every lab result

The person who enters a result cannot release it. Somebody else checks it first; until then it is marked provisional and kept out of the patient portal.

A corrected result marked amended with its reason, in front of the superseded value, which is struck through but still kept.

Amended, never overwritten

Correcting a released result needs a reason. The superseded value stays on the record, the result leaves the patient portal until it is checked again, and the report reads as amended.

A critical result shown in red and pinned above the rest of the queue.

Critical values

A result beyond the critical figures your laboratory sets is flagged on entry, shown in red, and stays above the verification queue until somebody records who they told.

Protecting data

How patient data is protected

Each of these is part of the product as shipped, and each can be shown to your IT team.

A padlock over a patient record whose contents are unreadable, labelled AES-256-GCM, with the key kept apart from it.

Encrypted at rest

Medical history, allergies and lab results are encrypted with AES-256-GCM, including every superseded value in a result's amendment history. The key is held outside the database.

A chain of numbered log entries, linked one to the next, ending in a seal.

A signed activity log

Every entry is signed. Editing, forging, renumbering or deleting entries, including the newest ones, is detectable, and the log can be checked on demand.

A phone showing a six-digit one-time code, beside a list of recovery codes with one used and crossed out.

Two-factor sign-in

One-time codes from an authenticator app (TOTP), with single-use recovery codes for a lost phone.

Failed password attempts stopped by a lowered barrier, with an hourglass.

Sign-in throttling

Repeated failed sign-ins are throttled per account, and the person making them cannot clear the count.

Three separate vaults, each holding its own database.

A database of your own

On the hosted edition, each hospital's records are kept in their own database, not in a shared table with a hospital column.

A server rack inside a building, with the cloud and the internet connection both crossed out.

Or your own server

The self-hosted edition runs inside your network with no internet connection at all. Patient data never leaves your server.

Sign-ins on the record

Sign-ins, sign-outs and failed sign-ins go into the same signed log. It names the account attempted and never stores what was typed.

Access by role

Seven roles, each reaching only the pages its work needs. The check runs on every page request, not only in the menu.

Protected forms

Every request that changes data must carry a token from your own screen, so another site cannot submit a form on a signed-in user's behalf.

Your data

Getting your data out

The records are yours, in formats other software can read.

A database on your own server exporting a SQL dump and a zip of documents into a box, with the key tied to it, and one patient's record as a FHIR R4 bundle.

Self-hosted backups

The built-in backup writes a plain MySQL dump and a zip of uploaded documents. It is your server: nothing is withheld and there is nothing to ask for. The dump is ordinary MySQL and the code is ordinary PHP, so it can be restored on other hardware.

One patient, as FHIR R4

Professional plan and above

A FHIR R4 document bundle for a single patient, covering encounters, conditions, prescriptions, observations, lab reports and allergies. Part of the Health ID and consent module.

Keep the key safe

Restoring a dump on another server needs your application key as well. Without it the encrypted fields cannot be read, and nothing tells you so at the time. Keep the key safe, and make sure it goes wherever a restore goes.

Plain statements

What we do not claim

A hospital that has been over-promised before should hear these from us first.

ABHA-ready, not gateway-connected

For hospitals in India: ABHA-ready — record ABHA numbers and manage patient consent, ready for ABDM integration. The connection to the national gateway is on the roadmap; the software does not connect to it today. Hospitals in other countries do not see it.

No accreditation claims

We do not describe the product as meeting any external accreditation or regulatory standard. That is for an auditor to judge, not for a vendor to declare.

Not a complete drug reference

The prescribing checks are a starter set of common interactions and drug allergies. They warn, they do not block, and they do not replace a licensed drug database or the prescriber's judgement.

No figures we have not measured

We publish no savings percentages, sizing or availability figures. Where a number would have to be measured first, we leave it out rather than guess.

Ask us to show you any line on this page

Book a demo and bring your IT team's questions. We will show each of these in the software, and tell you plainly where it stops.