Data Security
Healthcare data is sensitive. We treat it that way — with enterprise-grade security at every layer.
AES-256 Encryption
All data at rest is encrypted using AES-256, the same standard used by banks and governments worldwide.
TLS 1.3 in Transit
All data transmitted between your browser and our servers uses TLS 1.3, preventing interception.
India-Based Servers
All personal health data is stored on servers physically located in India, compliant with DPDPA 2023.
Regular Audits
We conduct quarterly penetration tests and annual security audits by independent certified firms.
Role-Based Access
Healthcare data is accessible only to authorised users with role-specific permissions. No blanket access.
NBTC Compliance
Our data handling for blood management complies with National Blood Transfusion Council guidelines.
Incident Response
In the event of a data breach, we will notify affected users within 72 hours in compliance with DPDPA 2023. We maintain a dedicated Security Incident Response Team (SIRT) available 24x7.
Report a Vulnerability
We run a responsible disclosure programme. If you discover a security vulnerability, please report it to security@omnexahealthtech.com. We aim to respond within 24 hours.