Skip to content
Ozrit Logo

Compliance & Security

Built to pass regulatory scrutiny

For healthcare and fintech buyers, security isn't a feature request — it's a precondition for being shortlisted. Here's exactly what OZRIT designs for.

Standards we design for

What each standard means in the architecture, not just the pitch deck

HIPAA

US healthcare data

Health Insurance Portability and Accountability Act

  • Encryption of protected health information (PHI) at rest and in transit
  • Role-based access control, scoped to the minimum data a role actually needs
  • Immutable audit trails for every access to, and change of, patient data
  • Business Associate Agreements (BAAs) with OZRIT and any sub-processors
  • Breach detection and notification workflows built into the system

PCI-DSS

Card payment data

Payment Card Industry Data Security Standard

  • Tokenization, so raw card numbers are never stored where it can be avoided
  • Network segmentation isolating the cardholder data environment
  • Encrypted transmission of cardholder data end to end
  • Restricted, logged access to payment infrastructure
  • Regular vulnerability scanning and secure coding practices against the OWASP Top 10

ABDM

India healthcare interoperability

Ayushman Bharat Digital Mission

  • ABHA (Ayushman Bharat Health Account) ID integration for patient identity
  • FHIR-based interoperability for structured health records
  • Consent Manager architecture, so patients control who can access their records
  • Data linkage handled per the National Digital Health Blueprint

RBI

Payments & fintech systems in India

Reserve Bank of India guidelines

  • Data localization — payment system data stored exclusively on servers within India
  • Secure API and webhook design for payment and transaction flows
  • Comprehensive, tamper-evident audit trails for every financial transaction
  • Multi-factor authentication on sensitive operations

DPDP Act

India personal data protection

Digital Personal Data Protection Act, 2023

  • Explicit, auditable consent capture and management
  • Purpose limitation — data used only for what it was collected for
  • Data minimization and defined retention limits
  • Built-in mechanisms for Data Principal rights: access, correction, and erasure requests
  • Breach notification workflows
Certifications

Where we stand today

ISO/IEC 27001:2022Certified

OZRIT is ISO/IEC 27001:2022 certified for information security management — independently audited controls for access management, encryption, audit logging, and incident response, not just internal policy.

ISO 9001:2015Certified

OZRIT is also ISO 9001:2015 certified for quality management — a documented, audited process for how we plan, deliver, and continuously improve engineering work, not just a one-off promise.

Alongside these certifications, the standards above and the deliverables below are how we make our security posture verifiable on a specific project, rather than asking you to take a badge on faith.

What you receive

Compliance deliverables, not just a checkbox

Security architecture document

How data flows through the system, where it's encrypted, who can access what, and why.

Signed Business Associate Agreement (BAA)

For engagements handling protected health information under HIPAA.

Data Processing Agreement (DPA)

Setting out how personal data is processed, in line with the DPDP Act.

Penetration test / security assessment report

An independent look at the system's attack surface before it goes live.

Which of these apply depends on your engagement and industry — a BAA only makes sense for HIPAA-relevant work, for instance. We'll confirm exactly what you get during scoping.

Evaluating OZRIT for a regulated project?

Talk to our team about the specific compliance requirements for your engagement.

Talk to our team