Data Security Statement

v1.1First published: 15 October 2025Last updated: 1 September 2026Effective: 1 October 2026

This statement details the security measures Narra Technologies Private Limited implements to protect your data from unauthorized access, misuse, loss, or corruption. It covers both healthcare and commerce deployments; the health-data provisions apply to healthcare deployments only.

Executive Summary

  • AES-256 encryption for all stored data
  • TLS 1.3 for all data in transit
  • All customer data hosted on Google Cloud Platform in asia-south1 (Mumbai, India)
  • 24/7 automated threat detection
  • Breach notification within 72 hours, and without undue delay
  • Aligned to the EU and UK GDPR and to HIPAA, and to applicable local data protection law including India's DPDP Act 2023
  • ISO/IEC 27001:2022 and SOC 2 Type II: work in progress, not yet certified. No certificate or report has been issued to us
  • Quarterly penetration testing
  • Zero-trust architecture
  • Complete audit trail of all data access

Every claim on this page is meant to be verifiable. Where something is planned rather than done, this document says so.

Security Commitment & Philosophy

Zero-Trust Principles

  • Never Trust, Always Verify: every user, device, and request is authenticated
  • Least Privilege Access: minimum permissions for each role
  • Defense in Depth: encryption, authentication, monitoring
  • Continuous Improvement: regular audits and penetration testing

Narra's Responsibilities

  • Securing infrastructure
  • Encryption and access controls
  • Secure software development
  • Monitoring for threats
  • Breach notification

User Responsibilities

  • Protecting login credentials
  • Enabling multi-factor authentication
  • Using secure networks
  • Reporting suspicious activity

Data Classification & Sensitivity

Classification Examples Security Level Retention
Public Blog posts, anonymized statistics Standard As needed
Internal Employee records High Per policy
Confidential Business strategies, customer commercial data Very High Per legal requirement
Restricted / PHI Health records, diagnoses MAXIMUM Life of the account, then deleted within 30 days

The retention periods here are the same as those in the Privacy Policy, the Terms of Service, the Data Processing Agreement, and the Business Associate Agreement.

Data Minimization

  • We don't request data we don't need
  • We don't retain longer than necessary
  • We de-identify when possible

Encryption & Cryptography

Encryption at Rest

All stored data is encrypted using AES-256. The following data types are encrypted:

  • Patient health records
  • Test results and diagnostic data
  • Medications and prescriptions
  • Clinical notes
  • Customer, order, and catalogue records in commerce deployments
  • Contact and billing information

Key Management

  • Keys managed in Google Cloud KMS
  • Keys never stored with encrypted data
  • Annual key rotation
  • Key access requires MFA

Encryption in Transit

TLS 1.3 is used for all web traffic, mobile app data, API calls, email, and file transfers.

Access Control & Authentication

Authentication Methods

  • Email & password: bcrypt hashed, minimum 12 characters
  • Multi-factor authentication: TOTP, SMS OTP, Biometric; mandatory for providers
  • Session management: 30-minute timeout, secure HttpOnly cookies, CSRF tokens
  • Password reset: time-limited tokens

Role-Based Access Control

Role Permissions Data Access
Patient View own records Own health data only
Provider View + add notes Only patients in their care
Clinic Admin Manage staff and billing De-identified analytics
Support Resolve tickets No direct health data
Developer Maintain infrastructure Encrypted data only
Security Monitor threats Audit logs and encrypted data

Infrastructure & Hosting

Cloud Provider

Google Cloud Platform. The production hosting region is asia-south1 (Mumbai, India), which is the primary region for all customers today, with disaster recovery within India. This meets India's data residency expectations under the DPDP Act.

We do not use Amazon Web Services. Earlier versions of this corpus listed AWS as a sub-processor and as a key store; that was inaccurate and has been corrected across every document.

Regional residency

Additional residency regions, including the EU, the UK, and the United States, are on the roadmap and are not available today. We do not offer a contractual residency commitment outside India at this time. If regional residency is a procurement requirement for you, raise it before signing so it can be recorded in an Order Form, or so we can tell you honestly that we cannot yet meet it.

Components

The platform runs on Cloud Run for application compute, Cloud SQL and MongoDB Atlas for persistent storage, Cloud Storage for documents and imaging, Cloud Load Balancing at the edge, and a private VPC for internal traffic.

High Availability

99.5% uptime SLA, multi-AZ deployment, auto-failover, and recovery time under 5 minutes.

Physical Security

Google data centres feature biometric access controls, 24/7 security personnel, and continuous surveillance.

Network Security

Web Application Firewall

Google Cloud Armor protects against SQL injection, XSS, and CSRF attacks.

Network Segmentation

The network is divided into four zones: Public (Web), Private (App/DB), Restricted (Admin), and Data (Storage).

DDoS Protection

Google Cloud Armor provides L3/L4/L7 protection with rate limiting and behavioral analysis.

Access Controls

VPN is required for all internal access. Only HTTPS (port 443) is accepted for incoming traffic.

Application Security

Secure Development Lifecycle

  • All code reviewed by two or more developers
  • Automated SAST and dependency scanning on every commit
  • Secrets managed in Google Secret Manager: no hardcoded secrets
  • Regular penetration testing

OWASP Top 10 Mitigations

The OWASP Top 10 is an awareness document, not a certifiable standard, so no compliance can be claimed against it. What we can state is how our controls map to it.

Vulnerability Mitigation
Injection Parameterized queries, input validation
Broken Authentication MFA, secure sessions
Sensitive Data Exposure AES-256, TLS 1.3
XXE Disabled external entities
Broken Access Control RBAC, least privilege
Security Misconfiguration Secure defaults, regular audits
XSS Input validation, CSP
Using Known Vulnerable Components Dependency scanning, patching
Insufficient Logging Comprehensive logging, 24/7 alerts

Data Backup & Disaster Recovery

Backup Strategy

Hourly replication and daily snapshots. Primary location: Mumbai; secondary location: secondary India region. All backups are encrypted with AES-256. Monthly restore tests are conducted. RTO for critical systems is under 4 hours.

Retention & Deletion

  • Health and business records retained for the life of the account, then irreversibly deleted within 30 days, except where a longer period is required by law
  • Backups retained for 30 days after primary deletion, then overwritten
  • Audit logs retained for 5 years, or the longer period required by applicable law
  • Billing and tax records retained for the period required by the tax law of your billing jurisdiction, which is 7 years in India
  • Deletion performed via secure overwrite and crypto-erase, with a certificate of deletion available on request

These are the same retention periods as the Privacy Policy, Terms of Service, Data Processing Agreement, and Business Associate Agreement.

Monitoring & Threat Detection

24/7 Monitoring

Continuous monitoring via Google Cloud Logging, Security Command Center, and Cloud Monitoring. Automated alerts are triggered for:

  • Failed login attempts
  • Impossible travel detection
  • Privilege escalation
  • Data exfiltration patterns

Incident Escalation

Tier 1
Automated response
Tier 2
Security analyst: response within 15 minutes
Tier 3
Security manager: response within 30 minutes
Tier 4
Security and legal leadership: response within 1 hour

Incident Response & Breach Management

Severity Classification

Severity Definition Response Time
Critical Health data compromised < 30 minutes
High Significant vulnerability identified < 2 hours
Medium Contained incident < 4 hours
Low Policy violation < 24 hours

Breach Notification Timeline

These are the same timelines as the Data Processing Agreement, the Business Associate Agreement, and the Privacy Policy.

  • Detection, isolation, containment: without undue delay, and in any event within 1 hour of detection
  • Investigation: scope, impact, and root cause within 24 hours
  • Notification to a customer acting as controller: without undue delay, and in any event within 24 hours; within 1 hour for a breach assessed as critical
  • Notification to a supervisory authority: without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to individuals (GDPR Article 33)
  • Notification to affected individuals: without undue delay where the risk is high, and within 72 hours where India's DPDP Act applies. Where HIPAA applies, individual notice is given no later than 60 calendar days from discovery, with notice to the US Department of Health and Human Services, and to prominent media for a breach affecting 500 or more individuals.
  • Post-incident review: following resolution, with the record retained for 5 years

To report a suspected breach or a security vulnerability, contact security@narrahealthcare.com. Please give us a reasonable period to remediate before public disclosure. We do not take legal action against good-faith security research that respects customer data and this request.

Compliance & Contact

Certification status

Stated plainly, so that a security reviewer does not have to interpret it. Nothing below is claimed as achieved unless it says so.

Standard Status
ISO/IEC 27001:2022 Implementation in progress. Not certified. No certificate has been issued to us. (ISO/IEC 27001:2013, cited in earlier versions of this page, was withdrawn; 27001:2022 is the current standard.)
SOC 2 Type II Readiness work in progress. No report has been issued. We will make one available under NDA once it exists.
OWASP Top 10 Controls mapped, as set out in Application Security. Not a certifiable standard.
Penetration testing Conducted quarterly by an independent external firm. Summary report available under NDA.

Regulatory alignment

Our controls are built to meet the EU and UK GDPR, the HIPAA Security Rule at 45 CFR 164.308, 164.310 and 164.312, and applicable local data protection and health data law, including India's DPDP Act 2023 and NABH and NABL standards. We describe this as alignment, not certification: no regulator certifies compliance with GDPR or HIPAA.

Contact

Entity
Narra Technologies Private Limited, Hyderabad, Telangana, India
Security questions and vulnerability reports
security@narrahealthcare.com: response within 24 hours
Data protection and the Data Protection Officer
dpo@narrahealthcare.com: response within 5 business days
Contracts and legal notices
legal@narrahealthcare.com

Compliance documentation, including our security controls schedule, penetration test summaries, and transfer impact assessment, is available on request under a signed NDA. Customers also have the audit and information rights set out in the Data Processing Agreement.