Security & privacy
Patient information deserves plain answers.
What Mitra does, what it does not, and what we will not claim.
Access controls
Access to patient information is limited to authenticated users.
Role-based permissions
Reception, doctors and administrators see and change different things. Procedure master data is admin-only.
Data protection
Patient information is protected in transit and at rest using industry-standard practices.
Auditability where supported
Key actions are logged where the product supports it. Scope is reviewed in your demo.
Infrastructure
Hosted on reputable cloud infrastructure. Details are shared during security review.
Data handling
Mitra processes communication and operational data to run your workflows. It is not used to make clinical decisions.
Backup practices where supported
Backup arrangements are confirmed per deployment.
Human access controls
Access by Aivry personnel is restricted and governed by internal policy.
Aivry certifications
Held by Aivry.
These are Aivry’s organisation-level certifications and registrations.
- ISO 27001:2022
- ISO 9001:2015
- DPIIT
We do not claim HIPAA compliance or certification, ABDM certification, SOC 2, GDPR certification or FHIR compliance. If that changes and is verified, this page will say so.
AI safety
Designed to know its limits.
This is behaviour in the product, not only copy on this page.
Mitra never fabricates
- Procedure prices
- Doctor availability
- Treatment recommendations
- Medical advice
- Diagnosis
- Medication instructions
- Clinical outcomes
Instead, Mitra
- Answers only from approved clinic information
- Says “I don’t have confirmed information about that” when it has none
- Escalates to a human when clinical judgement is required
- Hands over with the full conversation
Questions for your security team?
Bring them to the demo. We’ll answer what we can and say plainly what we can’t.
