Trust
Your data has only one owner. YOU!
- Only you can open your health records — no other user, no doctor without your booking.
- We never sell your data or use your locker files for advertising.
- We ask your permission separately — at signup, at every booking, and at every upload.
Standards
Certified today. Building for tomorrow.
We hold ourselves to recognised standards — and we tell you plainly which ones are done and which are on the way.
ISO 9001:2015
Quality management certified company.
Certificate QIBPK1570
ISO/IEC 27001
Information security management certification.
In progress
ABDM integration
Connecting to India's national digital health network.
In progress
ABHA ID linking
Link your ABHA health ID to your Nirogi Sathi locker.
In progress
Data security for patients
- Your records are for your eyes only.
- Every file is encrypted before it leaves our server.
- Booking details go only to the doctor you choose.
- Every view and download of your file is logged.
- Delete your account and data any time.
Data security for doctors & partners
- Doctor and hospital data is hosted on our own private server.
- Admin access is protected by 2-step verification.
- Patients share only what they consent to, per appointment.
- We do not sell directory or patient data to anyone.
- Every connection is HTTPS-only, enforced by the browser.
Where your data lives
Health records in India. Kept apart from everything else.
Your phone
Nirogi Sathi app or website
Amazon Web Services
Mumbai, India
AES-256 encrypted by us, then encrypted again at rest by AWS.
Nirogi private server
Our own infrastructure
No health record files are stored here.
Triple consent
We ask. Three separate times.
No blanket permission. Each consent is shown in Hindi and English, and nothing moves until you tap “I consent”.
- 1
When you sign up
You read and accept the Terms of Service and Privacy Policy. The box starts unticked.
I consent - 2
When you book a doctor
Your name, mobile and booking details go only to the doctor you picked — only for that appointment.
I consent - 3
When you upload a record
You confirm the upload and that the file will be encrypted with AES-256 and stored on AWS.
I consent
17 safeguards
Every lock on your locker
Where it lives
Stays in India
Health records are stored on AWS servers in Mumbai — your data does not leave the country.
Private cloud storage
Records sit in a private storage bucket. Nothing is in a public folder or a public link.
Kept apart from the app
Health files live on AWS, separate from the server that runs our website and app.
Built not to lose files
AWS storage is designed for 99.999999999% durability, so a disk failure does not lose your reports.
How it is locked
AES-256 encryption
Every health record is encrypted with AES-256-GCM before it is saved — the standard banks use.
Encrypted twice
On top of our encryption, AWS encrypts every stored file again at rest.
Policy numbers hidden
Insurance policy numbers are stored encrypted, not as plain text.
Links that expire
Files open only through short-lived signed links. A copied link stops working within minutes.
Owner-only access
The server checks that a file is yours before opening it. Other users get a “not yours” error.
Every access logged
Each view and download is recorded and the log is kept for 18 months.
Who gets in
Safer OTP login
One-time codes are stored hashed, expire in 10 minutes, and repeated attempts are blocked.
2-step verification for staff
Our admin panel uses authenticator-app codes before anyone can open patient files.
HTTPS everywhere
All traffic is encrypted in transit, and browsers are told never to use an insecure connection.
Hardened against attacks
Security headers block clickjacking, content sniffing and unwanted device access.
Uploads are checked
Every file's real type is verified on upload, so disguised or harmful files are rejected.
Delete any time
Remove your account and data whenever you want, from the app or our website.
Triple consent
Separate permission at signup, at every doctor booking, and at every health record upload.
Questions about your data?
Write to our grievance officer. You can also read the full privacy policy or delete your account.