Data Security Statement

v1.0First published: 15 October 2025Last updated: 14 January 2026Effective: 1 February 2026

This statement details the comprehensive security measures NarraHealth Technologies Pvt. Ltd. implements to protect your health data from unauthorized access, misuse, loss, or corruption.

Executive Summary

  • AES-256 encryption for all stored data
  • TLS 1.3 for all data in transit
  • All health data stored in India (GCP India regions)
  • 24/7 automated threat detection
  • Breach notification within 72 hours (DPDP Act)
  • DPDP Act 2023, GDPR-ready, HIPAA-equivalent
  • ISO 27001 & SOC 2 Type II (certified or in progress)
  • Quarterly penetration testing
  • Zero-trust architecture
  • Complete audit trail of all data access

Security Commitment & Philosophy

Zero-Trust Principles

  • Never Trust, Always Verify: every user, device, and request is authenticated
  • Least Privilege Access: minimum permissions for each role
  • Defense in Depth: encryption, authentication, monitoring
  • Continuous Improvement: regular audits and penetration testing

Narra Healthcare Responsibilities

  • Securing infrastructure
  • Encryption and access controls
  • Secure software development
  • Monitoring for threats
  • Breach notification

User Responsibilities

  • Protecting login credentials
  • Enabling multi-factor authentication
  • Using secure networks
  • Reporting suspicious activity

Data Classification & Sensitivity

Classification Examples Security Level Retention
Public Blog posts, anonymized statistics Standard As needed
Internal Employee records High Per policy
Confidential Business strategies Very High Per legal requirement
Restricted / PHI Health records, diagnoses MAXIMUM Indefinite or per request

Data Minimization

  • We don't request data we don't need
  • We don't retain longer than necessary
  • We de-identify when possible

Encryption & Cryptography

Encryption at Rest

All stored data is encrypted using AES-256. The following data types are encrypted:

  • Patient health records
  • Test results and diagnostic data
  • Medications and prescriptions
  • Clinical notes
  • Contact and billing information

Key Management

  • Keys managed in AWS KMS and Google Cloud KMS
  • Keys never stored with encrypted data
  • Annual key rotation
  • Key access requires MFA

Encryption in Transit

TLS 1.3 is used for all web traffic, mobile app data, API calls, email, and file transfers.

Access Control & Authentication

Authentication Methods

  • Email & password: bcrypt hashed, minimum 12 characters
  • Multi-factor authentication: TOTP, SMS OTP, Biometric; mandatory for providers
  • Session management: 30-minute timeout, secure HttpOnly cookies, CSRF tokens
  • Password reset: time-limited tokens

Role-Based Access Control

Role Permissions Data Access
Patient View own records Own health data only
Provider View + add notes Only patients in their care
Clinic Admin Manage staff and billing De-identified analytics
Support Resolve tickets No direct health data
Developer Maintain infrastructure Encrypted data only
Security Monitor threats Audit logs and encrypted data

Infrastructure & Hosting

Cloud Provider

Google Cloud Platform, India regions (asia-south1 and asia-south2). Meets India data residency requirements under the DPDP Act.

Components

Cloud Run, Cloud SQL, Cloud Storage, Cloud Load Balancing, VPC.

High Availability

99.5% uptime SLA, multi-AZ deployment, auto-failover, and recovery time under 5 minutes.

Physical Security

Google data centres feature biometric access controls, 24/7 security personnel, and continuous surveillance.

Network Security

Web Application Firewall

Google Cloud Armor protects against SQL injection, XSS, and CSRF attacks.

Network Segmentation

The network is divided into four zones: Public (Web), Private (App/DB), Restricted (Admin), and Data (Storage).

DDoS Protection

Google Cloud Armor provides L3/L4/L7 protection with rate limiting and behavioral analysis.

Access Controls

VPN is required for all internal access. Only HTTPS (port 443) is accepted for incoming traffic.

Application Security

Secure Development Lifecycle

  • All code reviewed by two or more developers
  • Automated SAST and dependency scanning on every commit
  • Secrets managed in Google Secret Manager: no hardcoded secrets
  • Regular penetration testing

OWASP Top 10 Mitigations

Vulnerability Mitigation
Injection Parameterized queries, input validation
Broken Authentication MFA, secure sessions
Sensitive Data Exposure AES-256, TLS 1.3
XXE Disabled external entities
Broken Access Control RBAC, least privilege
Security Misconfiguration Secure defaults, regular audits
XSS Input validation, CSP
Using Known Vulnerable Components Dependency scanning, patching
Insufficient Logging Comprehensive logging, 24/7 alerts

Data Backup & Disaster Recovery

Backup Strategy

Hourly replication and daily snapshots. Primary location: Mumbai; secondary location: secondary India region. All backups are encrypted with AES-256. Monthly restore tests are conducted. RTO for critical systems is under 4 hours.

Retention & Deletion

  • Health records retained indefinitely
  • Backups retained for 30 days after deletion
  • Audit logs retained for 5 years (DPDP Act requirement)
  • Deletion performed via secure overwrite and crypto-erase

Monitoring & Threat Detection

24/7 Monitoring

Continuous monitoring via Google Cloud Logging, Security Command Center, and Cloud Monitoring. Automated alerts are triggered for:

  • Failed login attempts
  • Impossible travel detection
  • Privilege escalation
  • Data exfiltration patterns

Incident Escalation

Tier 1
Automated response
Tier 2
Security analyst: response within 15 minutes
Tier 3
Security manager: response within 30 minutes
Tier 4
CISO / Legal: response within 1 hour

Incident Response & Breach Management

Severity Classification

Severity Definition Response Time
Critical Health data compromised < 30 minutes
High Significant vulnerability identified < 2 hours
Medium Contained incident < 4 hours
Low Policy violation < 24 hours

Breach Notification Timeline

  • Detection and isolation: within 5 minutes
  • Investigation: within 24 hours
  • User notification: within 72 hours (DPDP Act)
  • Post-incident review: following resolution

To report a suspected breach, contact security@narra.health. Do not disclose suspected breaches publicly.

Compliance & Contact

Certifications

  • ISO 27001:2013 (in progress)
  • SOC 2 Type II (in progress)
  • OWASP Top 10 compliant

Regulatory Compliance

DPDP Act 2023 (India), GDPR-ready, HIPAA-equivalent, NABH and NABL standards.

Contact

Security questions
security@narra.health: response within 24 hours
Data protection
dpo@narra.health: response within 5 business days

Compliance documentation is available upon request with a signed NDA.