Patient data is sacred to us
We've built AmritSmile with security at the core — not bolted on. Here is exactly what we do to protect your clinic and your patients' data.
Security by design
All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Encryption keys are managed via a hardware security module and rotated quarterly.
Every user has a role: doctor, receptionist, admin, or owner. Each role sees only what it needs. Patient records are never exposed to unauthorised staff.
Every action taken in AmritSmile — record creation, updates, access, deletion — is logged with a timestamp and user identity. Immutable, exportable, always on.
Hosted on AWS data centres in India (ap-south-1). SOC 2 Type II compliant infrastructure. Network perimeter protected by WAF, DDoS mitigation and VPC isolation.
Full database backups run every 6 hours with point-in-time recovery enabled. Backups are replicated across two availability zones and retained for 30 days.
We commission independent third-party penetration tests annually and after major feature releases. Critical findings are patched within 48 hours.
What we comply with
Responsible disclosure
If you discover a security vulnerability in AmritSmile, please report it to us privately. We investigate all reports and respond within 48 hours. We do not pursue legal action against good-faith researchers.
Report a vulnerability