Patient trust,
engineered
A hospital system holds the most sensitive data a person has. We treat that as the design constraint everything else works around — not a checkbox at the end.
Data
Encryption everywhere
TLS 1.3 in transit, AES-256 at rest, and encrypted offline caches on ward devices. Database backups are encrypted with separately held keys.
Access
Role-based access
A cashier sees invoices, not diagnoses. A lab tech sees orders, not psychiatric notes. Access maps to clinical role, and break-glass access is logged and reviewed.
Accountability
Complete audit trail
Every view, edit, print and export of a patient record is logged — who, what, when, from which device. Logs are append-only and retained for seven years.
Residency
Data residency
Production data is hosted in-region with replicated failover. Network plans can choose dedicated infrastructure, including on-premise for county deployments.
Continuity
Uptime & recovery
Continuous backups, engineered for 99.95% uptime. Recovery point under 5 minutes, recovery time under 1 hour — and wards run offline through any of it.
Assurance
Tested by outsiders
Independent penetration testing on a twice-yearly cadence, a private disclosure programme for researchers, and dependency scanning on every release.
Built for the rules you answer to
Kenya Data Protection Act, 2019
Registered data processor. DPIAs, consent flows and subject-access requests are product features, not paperwork.
Ministry of Health standards
Conforms to the Kenya Standards and Guidelines for E-Health, including HIE interoperability requirements.
HIPAA-aligned controls
Technical safeguards mapped to the HIPAA Security Rule for facilities working with international partners.
ISO 27001 (in progress)
The control framework is in place; certification audit is being scheduled.
Need the full security dossier?
Architecture diagrams, subprocessor list and pen-test summaries, under NDA.