Security & Data Protection

Clyno security: your patients' data stays yours

Clyno is AI clinic software for doctors and clinics in India, and the records it holds stay the clinic's own. It is hosted in secure data centres in India, encrypted end to end, and built around the principles of India's DPDP Act — with role-based access, audit logging and per-clinic isolation as the default, not an upsell.

Hosted in India 256-bit encryption DPDP-aligned Role-based access
How we protect data

Security that's on by default

Every clinic gets the same protections — there is no 'security tier'.

Hosted in India

Data lives in enterprise-grade data centres in India. Clinical data does not leave the country in normal operation.

Encrypted in transit & at rest

256-bit encryption on the wire and at rest, with industry-standard key management — keys are never embedded in the apps.

Role-based access control

Six roles, each scoped to exactly what it needs. Access is enforced on the server, not just hidden in the UI.

Audit logging

Sensitive actions are recorded, so a clinic can see who did what and when.

Per-clinic isolation

Every clinic is a separate tenant. One clinic can never read another's patient records.

Backups & recovery

Automated daily backups with fast recovery, so a mistake or outage doesn't mean lost records.

Secure sign-in

Strong login controls with OTP verification for sensitive roles, account lockout on repeated failures and automatic session protection.

No PHI on public screens

The waiting-room 'Now Serving' board shows tokens, not patient names — privacy by design.

Defence in depth

Multiple independent layers of protection stand between the internet and clinical data — reviewed and strengthened continuously.

India's DPDP Act

Built around the DPDP Act, 2023

India's Digital Personal Data Protection Act sets the rules for handling personal data. Clyno is designed around its core principles.

Purpose limitation — data captured for care is used for care
Data minimisation — we collect what a consultation needs, not more
Consent for patient communications (e.g. WhatsApp follow-ups)
A patient's right to access and correction of their record
Retention and erasure handled on request

Our honesty policy on certifications

We publish the security practices we actually run — not compliance badges we haven't earned. Clyno does not currently claim a formal HIPAA or ISO 27001 certification. As we scale, formal certification is on our roadmap, and we'll say so here the day it's real. Until then, what you read on this page is what the platform does today.

Frequently asked questions

In India, in enterprise-grade data centres. Your clinic's clinical data does not leave the country in normal operation.

Clyno is built for the Indian market and follows the principles of India's Digital Personal Data Protection (DPDP) Act, 2023. We do not currently claim a formal HIPAA or ISO 27001 certification — we publish our actual security practices honestly rather than badges we haven't earned. Formal certification is on our roadmap as we scale.

Every clinic is a separate tenant with its own isolation boundary, enforced on every request. One clinic's users can never read another clinic's records, and access is enforced on the server, not just in the app.

Yes — 256-bit encryption in transit and at rest, with industry-standard key management. Encryption keys are never embedded in the apps.

Access is role-based: superadmin, admin, doctor, staff, marketing and support each see only what their role needs. Sensitive actions are recorded in an audit log.

Yes. The clinic owns its patient data. You can export your records, and we follow DPDP principles on retention and erasure.

Security you can put in front of a patient

See exactly how Clyno handles clinical data — book a walkthrough with our team.

Related: EMR · ABDM & ABHA