Security

Security at Anxya Health

We describe our controls honestly. Anxya Health currently holds no third-party certifications (no SOC 2, ISO 27001/42001 or HITRUST) and has no independent penetration test on file yet. Items marked “owner-confirm” depend on our managed infrastructure providers and should be verified contractually for enterprise deployments.

ControlStatusNotes
Encryption in transit (TLS)ImplementedServed over HTTPS/TLS via the platform ingress.
Encryption at restOwner-confirmProvided by the managed database/storage layer — verify with provider.
AuthenticationImplementedJWT sessions with hashed passwords, email verification and password reset.
Brute-force / rate limiting on authAlignedLogin attempt throttling in place; enterprise WAF is an infra add-on.
Role-based access control (RBAC)ImplementedAdmin vs. user roles; workspace roles (owner/admin/member/viewer).
Tenant / data isolationImplementedAll user resources are scoped and ownership-checked per request.
Secrets managementImplementedSecrets are environment-injected, never committed or returned to clients.
Audit loggingAlignedKey actions are logged; centralized SIEM is an enterprise-deployment option.
Payment securityImplementedPayments via Razorpay with server-side HMAC signature verification; no card data stored.
Input handling (XSS/injection)ImplementedOutput sanitization (DOMPurify), parameterized queries, SSRF guards on URL fetch.
Dependency / secret scanningAlignedStandard tooling; formal SBOM available for enterprise on request.
Backups & disaster recoveryOwner-confirmProvided by the managed database layer — RPO/RTO to be confirmed per deployment.
MFA / SSO (SAML/OIDC)PlannedAvailable for qualifying enterprise deployments; contact us.
Independent penetration testNot heldNo third-party pentest report exists yet.
SOC 2 / ISO 27001 / HITRUSTNot heldNo certification or attestation currently exists.
Responsible vulnerability disclosure

We welcome good-faith security research. Please email security@anxya.health with details and reproduction steps. Do not access data that isn't yours, don't run service-degrading scans, and give us reasonable time to remediate before disclosure. We do not currently run a paid bug-bounty program. Our machine-readable policy is at /.well-known/security.txt.

Operated by Anxya Tech Private Limited (CIN: U62099PN2024PTC230490), Pune, Maharashtra, India.

We use cookies to run Anxya Health and improve your experience. Choose how we may use them. Read our Cookie Policy, Privacy Policy and Terms.