Patient trust,
engineered

A hospital system holds the most sensitive data a person has. We treat that as the design constraint everything else works around — not a checkbox at the end.

Data

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest, and encrypted offline caches on ward devices. Database backups are encrypted with separately held keys.

Access

Role-based access

A cashier sees invoices, not diagnoses. A lab tech sees orders, not psychiatric notes. Access maps to clinical role, and break-glass access is logged and reviewed.

Accountability

Complete audit trail

Every view, edit, print and export of a patient record is logged — who, what, when, from which device. Logs are append-only and retained for seven years.

Residency

Data residency

Production data is hosted in-region with replicated failover. Network plans can choose dedicated infrastructure, including on-premise for county deployments.

Continuity

Uptime & recovery

Continuous backups, engineered for 99.95% uptime. Recovery point under 5 minutes, recovery time under 1 hour — and wards run offline through any of it.

Assurance

Tested by outsiders

Independent penetration testing on a twice-yearly cadence, a private disclosure programme for researchers, and dependency scanning on every release.

Built for the rules you answer to

Kenya Data Protection Act, 2019

Registered data processor. DPIAs, consent flows and subject-access requests are product features, not paperwork.

Ministry of Health standards

Conforms to the Kenya Standards and Guidelines for E-Health, including HIE interoperability requirements.

HIPAA-aligned controls

Technical safeguards mapped to the HIPAA Security Rule for facilities working with international partners.

ISO 27001 (in progress)

The control framework is in place; certification audit is being scheduled.

Need the full security dossier?

Architecture diagrams, subprocessor list and pen-test summaries, under NDA.

Request documentation