Security & Compliance
Enterprise-grade security built for healthcare and high-stakes industries.
At Aizent Private Limited, we understand that in healthcare, data security isn't a feature—it's the foundation. As the Data Fiduciary under the Digital Personal Data Protection Act, 2023, our India-first infrastructure is architected from the ground up to keep patient information strictly confidential, secure, and compliant with Indian data-protection law (and aligned to global standards such as HIPAA where relevant).
Encryption & PII Redaction
All Personally Identifiable Information (PII) is masked and redacted dynamically in transcripts and summaries. Data in transit is secured using TLS 1.3, data at rest using AES-256, and call recordings are served only via short-lived signed URLs that expire.
India-First Cloud Infrastructure
Our platform runs on isolated, highly secure GCP infrastructure in the asia-south1 (Mumbai) region. We enforce strict per-organization tenant isolation, ensuring your data never co-mingles with other organizations' data, and stays within India as required by the DPDP Act.
Retention & Auto-Purge
A scheduled auto-purge enforces DPDP retention limits—recordings, transcripts and session reports after 90 days, sessions after 30 days, withdrawn consent after 180 days—with every run written to a retention audit log. Billing (7y) and audit logs (3y) are retained by law.
Access Control & Audits
Role-based access, consent registers, and erasure workflows back our DPDP controls. We conduct regular penetration testing, automated vulnerability scanning, and routine security audits to stay ahead of emerging threats.
Certifications & Compliance
DPDP Act, 2023 Compliant
As the registered Data Fiduciary, we implement consent-at-call-start, a consent register, data-principal erasure (right to deletion), and an automated 90-day retention purge with audit logging—ensuring transparent processing and robust data-principal rights for Indian citizens.
HIPAA-Aligned (US Equivalent)
While our primary regime is India's DPDP Act, we also align with the Health Insurance Portability and Accountability Act standards for protecting sensitive patient health information from being disclosed without consent or knowledge.
Need detailed security architecture?
Our team can provide a comprehensive security whitepaper and sign a Business Associate Agreement (BAA) for healthcare providers.
Contact Security Team