We describe our controls honestly. Anxya Health currently holds no third-party certifications (no SOC 2, ISO 27001/42001 or HITRUST) and has no independent penetration test on file yet. Items marked “owner-confirm” depend on our managed infrastructure providers and should be verified contractually for enterprise deployments.
| Control | Status | Notes |
|---|---|---|
| Encryption in transit (TLS) | Implemented | Served over HTTPS/TLS via the platform ingress. |
| Encryption at rest | Owner-confirm | Provided by the managed database/storage layer — verify with provider. |
| Authentication | Implemented | JWT sessions with hashed passwords, email verification and password reset. |
| Brute-force / rate limiting on auth | Aligned | Login attempt throttling in place; enterprise WAF is an infra add-on. |
| Role-based access control (RBAC) | Implemented | Admin vs. user roles; workspace roles (owner/admin/member/viewer). |
| Tenant / data isolation | Implemented | All user resources are scoped and ownership-checked per request. |
| Secrets management | Implemented | Secrets are environment-injected, never committed or returned to clients. |
| Audit logging | Aligned | Key actions are logged; centralized SIEM is an enterprise-deployment option. |
| Payment security | Implemented | Payments via Razorpay with server-side HMAC signature verification; no card data stored. |
| Input handling (XSS/injection) | Implemented | Output sanitization (DOMPurify), parameterized queries, SSRF guards on URL fetch. |
| Dependency / secret scanning | Aligned | Standard tooling; formal SBOM available for enterprise on request. |
| Backups & disaster recovery | Owner-confirm | Provided by the managed database layer — RPO/RTO to be confirmed per deployment. |
| MFA / SSO (SAML/OIDC) | Planned | Available for qualifying enterprise deployments; contact us. |
| Independent penetration test | Not held | No third-party pentest report exists yet. |
| SOC 2 / ISO 27001 / HITRUST | Not held | No certification or attestation currently exists. |
We welcome good-faith security research. Please email security@anxya.health with details and reproduction steps. Do not access data that isn't yours, don't run service-degrading scans, and give us reasonable time to remediate before disclosure. We do not currently run a paid bug-bounty program. Our machine-readable policy is at /.well-known/security.txt.
Operated by Anxya Tech Private Limited (CIN: U62099PN2024PTC230490), Pune, Maharashtra, India.
We use cookies to run Anxya Health and improve your experience. Choose how we may use them. Read our Cookie Policy, Privacy Policy and Terms.