This statement details the security measures Narra Technologies Private Limited implements to protect your data from unauthorized access, misuse, loss, or corruption. It covers both healthcare and commerce deployments; the health-data provisions apply to healthcare deployments only.
Every claim on this page is meant to be verifiable. Where something is planned rather than done, this document says so.
| Classification | Examples | Security Level | Retention |
|---|---|---|---|
| Public | Blog posts, anonymized statistics | Standard | As needed |
| Internal | Employee records | High | Per policy |
| Confidential | Business strategies, customer commercial data | Very High | Per legal requirement |
| Restricted / PHI | Health records, diagnoses | MAXIMUM | Life of the account, then deleted within 30 days |
The retention periods here are the same as those in the Privacy Policy, the Terms of Service, the Data Processing Agreement, and the Business Associate Agreement.
All stored data is encrypted using AES-256. The following data types are encrypted:
TLS 1.3 is used for all web traffic, mobile app data, API calls, email, and file transfers.
| Role | Permissions | Data Access |
|---|---|---|
| Patient | View own records | Own health data only |
| Provider | View + add notes | Only patients in their care |
| Clinic Admin | Manage staff and billing | De-identified analytics |
| Support | Resolve tickets | No direct health data |
| Developer | Maintain infrastructure | Encrypted data only |
| Security | Monitor threats | Audit logs and encrypted data |
Google Cloud Platform. The production hosting region is asia-south1 (Mumbai, India), which is the primary region for all customers today, with disaster recovery within India. This meets India's data residency expectations under the DPDP Act.
We do not use Amazon Web Services. Earlier versions of this corpus listed AWS as a sub-processor and as a key store; that was inaccurate and has been corrected across every document.
Additional residency regions, including the EU, the UK, and the United States, are on the roadmap and are not available today. We do not offer a contractual residency commitment outside India at this time. If regional residency is a procurement requirement for you, raise it before signing so it can be recorded in an Order Form, or so we can tell you honestly that we cannot yet meet it.
The platform runs on Cloud Run for application compute, Cloud SQL and MongoDB Atlas for persistent storage, Cloud Storage for documents and imaging, Cloud Load Balancing at the edge, and a private VPC for internal traffic.
99.5% uptime SLA, multi-AZ deployment, auto-failover, and recovery time under 5 minutes.
Google data centres feature biometric access controls, 24/7 security personnel, and continuous surveillance.
Google Cloud Armor protects against SQL injection, XSS, and CSRF attacks.
The network is divided into four zones: Public (Web), Private (App/DB), Restricted (Admin), and Data (Storage).
Google Cloud Armor provides L3/L4/L7 protection with rate limiting and behavioral analysis.
VPN is required for all internal access. Only HTTPS (port 443) is accepted for incoming traffic.
The OWASP Top 10 is an awareness document, not a certifiable standard, so no compliance can be claimed against it. What we can state is how our controls map to it.
| Vulnerability | Mitigation |
|---|---|
| Injection | Parameterized queries, input validation |
| Broken Authentication | MFA, secure sessions |
| Sensitive Data Exposure | AES-256, TLS 1.3 |
| XXE | Disabled external entities |
| Broken Access Control | RBAC, least privilege |
| Security Misconfiguration | Secure defaults, regular audits |
| XSS | Input validation, CSP |
| Using Known Vulnerable Components | Dependency scanning, patching |
| Insufficient Logging | Comprehensive logging, 24/7 alerts |
Hourly replication and daily snapshots. Primary location: Mumbai; secondary location: secondary India region. All backups are encrypted with AES-256. Monthly restore tests are conducted. RTO for critical systems is under 4 hours.
These are the same retention periods as the Privacy Policy, Terms of Service, Data Processing Agreement, and Business Associate Agreement.
Continuous monitoring via Google Cloud Logging, Security Command Center, and Cloud Monitoring. Automated alerts are triggered for:
| Severity | Definition | Response Time |
|---|---|---|
| Critical | Health data compromised | < 30 minutes |
| High | Significant vulnerability identified | < 2 hours |
| Medium | Contained incident | < 4 hours |
| Low | Policy violation | < 24 hours |
These are the same timelines as the Data Processing Agreement, the Business Associate Agreement, and the Privacy Policy.
To report a suspected breach or a security vulnerability, contact security@narrahealthcare.com. Please give us a reasonable period to remediate before public disclosure. We do not take legal action against good-faith security research that respects customer data and this request.
Stated plainly, so that a security reviewer does not have to interpret it. Nothing below is claimed as achieved unless it says so.
| Standard | Status |
|---|---|
| ISO/IEC 27001:2022 | Implementation in progress. Not certified. No certificate has been issued to us. (ISO/IEC 27001:2013, cited in earlier versions of this page, was withdrawn; 27001:2022 is the current standard.) |
| SOC 2 Type II | Readiness work in progress. No report has been issued. We will make one available under NDA once it exists. |
| OWASP Top 10 | Controls mapped, as set out in Application Security. Not a certifiable standard. |
| Penetration testing | Conducted quarterly by an independent external firm. Summary report available under NDA. |
Our controls are built to meet the EU and UK GDPR, the HIPAA Security Rule at 45 CFR 164.308, 164.310 and 164.312, and applicable local data protection and health data law, including India's DPDP Act 2023 and NABH and NABL standards. We describe this as alignment, not certification: no regulator certifies compliance with GDPR or HIPAA.
Compliance documentation, including our security controls schedule, penetration test summaries, and transfer impact assessment, is available on request under a signed NDA. Customers also have the audit and information rights set out in the Data Processing Agreement.