The stack behind the Dules.

Built cloud-native on GCP, event-driven across microservices, and ABDM-integrated from the first commit.

Architecture

Microservices. Event-driven. Cloud-native.

Each Dule runs as an independent Node.js microservice on GCP Cloud Run. Services communicate via an internal event bus, with no synchronous coupling. Angular 21 frontends are deployed to Firebase Hosting with global CDN. MongoDB Atlas handles clinical data with per-tenant encryption.

GCPCloud provider
Node.jsBackend runtime
Angular 21Frontend framework
FHIR R4Health data standard

Security & compliance

Patient data protection is not a feature. It is the foundation.

  • Information security management, roadmap target Q1 2027
  • PHI handling aligned with US healthcare privacy standards
  • India Digital Personal Data Protection Act 2023
  • Trust services criteria audit, roadmap target Q2 2027
PHI encryption at rest

AES-256 encryption for all patient records in MongoDB Atlas. Per-tenant DEK rotation.

Zero-trust network

All inter-service communication requires mTLS. No service trusts another by default.

Secret Manager

All credentials, API keys, and certificates stored in GCP Secret Manager, never in code.

Security monitoring

GCP Security Command Center + Cloud Audit Logs for continuous threat detection.

Transparency

Questions about our security posture?

We publish our security architecture and share audit reports with enterprise prospects under NDA.