Tenant isolation (RLS)
Every hospital's data lives behind PostgreSQL row-level security — one tenant can never read another's records, enforced at the database, not just the app.
Patient data is protected at every layer — database, application and network.
Every hospital's data lives behind PostgreSQL row-level security — one tenant can never read another's records, enforced at the database, not just the app.
Granular, editable roles and permissions govern who can see and do what, per module and per action.
Every sensitive action — logins, edits, exports, restores — is logged with who, what and when for compliance and forensics.
Consent-based record sharing, ABHA linking and care-context linking built to India's digital-health standards.
Cloudflare Turnstile captcha, per-IP brute-force rate limiting and short-lived JWT sessions with silent refresh.
Full backups of your setup and data run automatically on a schedule, with off-site copies and retention. Recovery is carried out by MediCore on request — your data is never a single point of failure.
Every control above is implemented and verified in production. MediCore is built to support India's DPDP Act and HIPAA-style safeguards; formal application-level certifications (e.g. ISO 27001, SOC 2) are on our roadmap.
These certifications are held by our infrastructure provider, OVHcloud, for the data centres MediCore runs on — they cover the hosting layer, not MediCore's application. View OVHcloud compliance ›
We'll set up a sandbox hospital for your team and walk you through it — no commitment.