Zyposoft
Data Security

Built secure,not secured afterwards.

Your data, your credentials and your clinical workflows are protected at every layer and we will show you exactly how, rather than asking you to take it on trust.

Encrypted in transitLeast privilegeRole and contextEverything recorded
Zyposoft security — protection at every layerAt a glance
Data encryptionEncrypted

TLS in transit, and the credentials the platform holds sealed with AES-256-GCM.

Credential securitySealed

Integration secrets kept apart from clinical data and tamper-checked on read.

Access controlLeast privilege

A named permission on every route, scoped to the caller's branch and role.

InfrastructureIsolated

Three isolated tiers; only the web tier is reachable from outside.

Where we are on compliance

ISO 27001
Under Progress
SOC 2
Under Progress
HIPAA
Under Progress
India DPDP Act
Under Progress

How we protect your data

Data encryption

Traffic between a browser, a ward tablet or a connected system and the platform runs over TLS, and the credentials the platform holds on your behalf are sealed with authenticated encryption.

  • Encrypted connections between your people and the platform
  • Passwords hashed with a memory-hard algorithm, never recoverable
  • Integration and portal credentials sealed, and tamper-checked on read
In transit
TLS at the edge, over an encrypted tunnel to the application
Passwords
scrypt (N=16384, r=8, p=1), 16-byte random salt, constant-time compare
Stored credentials
AES-256-GCM, with the authentication tag checked on every decrypt
Sessions
Signed tokens (JWT, HS256)
Integrity
SHA-256 across audit records and the custody chain
Credential security

The credentials that let us talk to your other systems live apart from clinical data, so a problem in one is not a problem in the other.

  • Integration credentials stored apart from workflow data
  • Held as ciphertext, worthless to anyone without the key
  • Replaceable without a code change, and versioned so the scheme can move on
What it covers
ABDM and ABHA configuration, and government portal logins
Cipher
AES-256-GCM: encrypted and authenticated in one step
Stored as
A versioned envelope: fresh nonce, ciphertext, authentication tag
Key
Supplied by the deployment environment, never held in the database
On read
The tag is checked first anything altered is refused, not used
Access control

Nobody gets a blanket key. Every route names the permission it needs, and every query is cut down to the caller's branch before it reaches the clinical record.

  • A named permission on every route, not a general login
  • Queries scoped to your branch and role before the domain sees them
  • Approvals and privilege grants cannot be signed off by the person asking
Per route
Each route names the permission it requires
Scoping
Queries cut to the caller's branch and role at the boundary
Separation
Approvals, verifications and grants cannot be self-authorised
Federation
OIDC single sign-on with your identity provider, where you want it
Record
Append-only audit trail, hash-chained on sensitive cases
Infrastructure

Application, data and messaging run on separate hosts. Only the web tier answers the outside world, so the database and the event bus are never sitting on the public network.

  • Three isolated tiers, each container reachable only from the one above it
  • Deployment model chosen with you, including fully on your own infrastructure
  • Tracing and metrics per service, so a fault points at the module that caused it
Web tier
Reverse proxy and the application, TLS only, the single public surface
App tier
Core API, event bus and cache, reachable only from the web tier
Data tier
PostgreSQL, reachable only from the application tier
Services
Core API, AI copilot, device server and event worker, each isolated
Watching it
Tracing, metrics and dashboards attributable to a single module

Security architecture

Defence in depth, with no single point of trust

Every request passes through the same stack, and no single layer is load-bearing on its own. A failure in one should not hand anybody the data behind it.

Network
TLS 1.2 and 1.3Reverse proxy at the edgeWeb tier only public surfaceDatabase and bus unexposed
Application
Permission named per routeBranch-scoped queriesRate limitingModules talk by event, not table
Data
One relational record of truthBranch isolationEncrypted credential storeTyped data layer
Operations
Append-only audit trailSHA-256 hash chainsSeparation of dutiesDistributed tracing
Taken from the Zypocare One platform architecture: a modular core on one clinical record, separate runtime services, and isolated deployment tiers. The platform is under active development, so the exact topology for your own deployment is settled during implementation.
Zyposoft Technologies is a product engineering company based in Bangalore, building software for healthcare and enterprise operations. Our products are Zypocare One, the connected hospital platform; Zypo Clinical AI, which adds intelligence a clinician can overrule; and the Integration Platform that keeps them working with the systems already in place.
Products
Zypocare OneZypo Clinical AIIntegration Platform
Solutions
Healthcare TransformationEnterprise Product EngineeringAI and AutomationCloud, Data and Integration
Company
About ZyposoftLeadershipPartnersCareersContact
Get in touch
Bangalore, IN
#7, Nisarga Layout
Chikkalsandra
Bangalore 560061
India
info@zyposoft.com
Security & GovernanceIdentity & AccessData PrivacyData Security
© 2026 Zyposoft Technologies. All rights reserved.
Privacy PolicyTerms of UseSitemap