Skip to content

Security & privacy

Patient information deserves plain answers.

What Mitra does, what it does not, and what we will not claim.

Access controls

Access to patient information is limited to authenticated users.

Role-based permissions

Reception, doctors and administrators see and change different things. Procedure master data is admin-only.

Data protection

Patient information is protected in transit and at rest using industry-standard practices.

Auditability where supported

Key actions are logged where the product supports it. Scope is reviewed in your demo.

Infrastructure

Hosted on reputable cloud infrastructure. Details are shared during security review.

Data handling

Mitra processes communication and operational data to run your workflows. It is not used to make clinical decisions.

Backup practices where supported

Backup arrangements are confirmed per deployment.

Human access controls

Access by Aivry personnel is restricted and governed by internal policy.

Aivry certifications

Held by Aivry.

These are Aivry’s organisation-level certifications and registrations.

  • ISO 27001:2022
  • ISO 9001:2015
  • DPIIT

We do not claim HIPAA compliance or certification, ABDM certification, SOC 2, GDPR certification or FHIR compliance. If that changes and is verified, this page will say so.

AI safety

Designed to know its limits.

This is behaviour in the product, not only copy on this page.

Mitra never fabricates

  • Procedure prices
  • Doctor availability
  • Treatment recommendations
  • Medical advice
  • Diagnosis
  • Medication instructions
  • Clinical outcomes

Instead, Mitra

  • Answers only from approved clinic information
  • Says “I don’t have confirmed information about that” when it has none
  • Escalates to a human when clinical judgement is required
  • Hands over with the full conversation

Questions for your security team?

Bring them to the demo. We’ll answer what we can and say plainly what we can’t.