Compliance & Security
Built to pass regulatory scrutiny
For healthcare and fintech buyers, security isn't a feature request — it's a precondition for being shortlisted. Here's exactly what OZRIT designs for.
What each standard means in the architecture, not just the pitch deck
HIPAA
US healthcare dataHealth Insurance Portability and Accountability Act
- Encryption of protected health information (PHI) at rest and in transit
- Role-based access control, scoped to the minimum data a role actually needs
- Immutable audit trails for every access to, and change of, patient data
- Business Associate Agreements (BAAs) with OZRIT and any sub-processors
- Breach detection and notification workflows built into the system
PCI-DSS
Card payment dataPayment Card Industry Data Security Standard
- Tokenization, so raw card numbers are never stored where it can be avoided
- Network segmentation isolating the cardholder data environment
- Encrypted transmission of cardholder data end to end
- Restricted, logged access to payment infrastructure
- Regular vulnerability scanning and secure coding practices against the OWASP Top 10
ABDM
India healthcare interoperabilityAyushman Bharat Digital Mission
- ABHA (Ayushman Bharat Health Account) ID integration for patient identity
- FHIR-based interoperability for structured health records
- Consent Manager architecture, so patients control who can access their records
- Data linkage handled per the National Digital Health Blueprint
RBI
Payments & fintech systems in IndiaReserve Bank of India guidelines
- Data localization — payment system data stored exclusively on servers within India
- Secure API and webhook design for payment and transaction flows
- Comprehensive, tamper-evident audit trails for every financial transaction
- Multi-factor authentication on sensitive operations
DPDP Act
India personal data protectionDigital Personal Data Protection Act, 2023
- Explicit, auditable consent capture and management
- Purpose limitation — data used only for what it was collected for
- Data minimization and defined retention limits
- Built-in mechanisms for Data Principal rights: access, correction, and erasure requests
- Breach notification workflows
Where we stand today
OZRIT is ISO/IEC 27001:2022 certified for information security management — independently audited controls for access management, encryption, audit logging, and incident response, not just internal policy.
OZRIT is also ISO 9001:2015 certified for quality management — a documented, audited process for how we plan, deliver, and continuously improve engineering work, not just a one-off promise.
Alongside these certifications, the standards above and the deliverables below are how we make our security posture verifiable on a specific project, rather than asking you to take a badge on faith.
Compliance deliverables, not just a checkbox
Security architecture document
How data flows through the system, where it's encrypted, who can access what, and why.
Signed Business Associate Agreement (BAA)
For engagements handling protected health information under HIPAA.
Data Processing Agreement (DPA)
Setting out how personal data is processed, in line with the DPDP Act.
Penetration test / security assessment report
An independent look at the system's attack surface before it goes live.
Which of these apply depends on your engagement and industry — a BAA only makes sense for HIPAA-relevant work, for instance. We'll confirm exactly what you get during scoping.
Evaluating OZRIT for a regulated project?
Talk to our team about the specific compliance requirements for your engagement.
Talk to our team