Trust & Safety

Data Security

Healthcare data is sensitive. We treat it that way — with enterprise-grade security at every layer.

🔐

AES-256 Encryption

All data at rest is encrypted using AES-256, the same standard used by banks and governments worldwide.

🛡️

TLS 1.3 in Transit

All data transmitted between your browser and our servers uses TLS 1.3, preventing interception.

🇮🇳

India-Based Servers

All personal health data is stored on servers physically located in India, compliant with DPDPA 2023.

🔍

Regular Audits

We conduct quarterly penetration tests and annual security audits by independent certified firms.

🔑

Role-Based Access

Healthcare data is accessible only to authorised users with role-specific permissions. No blanket access.

📋

NBTC Compliance

Our data handling for blood management complies with National Blood Transfusion Council guidelines.

Incident Response

In the event of a data breach, we will notify affected users within 72 hours in compliance with DPDPA 2023. We maintain a dedicated Security Incident Response Team (SIRT) available 24x7.

Report a Vulnerability

We run a responsible disclosure programme. If you discover a security vulnerability, please report it to security@omnexahealthtech.com. We aim to respond within 24 hours.