Your patient data, on your terms.
Therapy centres handle some of the most sensitive data in healthcare — children's names, diagnoses, parent contacts. We've built TheraFlow so you stay in control of that data, can audit what we touch, and can take everything with you anytime.
Last reviewed 7 June 2026
We hold the minimum
Many fields (Aadhaar, ABHA ID, full address, medical history) are optional. Skip them and we never store them. You decide what enters the system.
Encrypted everywhere
AES-256 encryption at rest (AWS RDS) and TLS 1.3 in transit. No customer data ever leaves the encrypted boundary in plain text.
Strict per-tenant isolation
Every database query is filtered by your centre's tenant_id. Our application layer cannot return another centre's data even by mistake.
AI features are opt-in
Scheduling AI, report generation, and clinical reasoning are off by default. You turn them on per feature, knowing exactly when data flows to an LLM. Anthropic and Google do not train on our API calls.
You can see what we touched
Per-centre activity log: who accessed which patient record, when, from where. Available to admins from Settings.
Take everything, anytime
One-click export of every patient, appointment, note, and invoice as JSON/CSV. If you ever leave, you leave with all your data.
Delete on your terms
Wipe a single patient or your entire centre. 30-day grace period to restore, then irreversible deletion across all backups within 60 days.
Breach notification — 72 hours
If we ever discover a security incident affecting your data, you and India's Data Protection Board are notified within 72 hours, with everything we know.
Where your data lives
All customer data — primary, backups, files, email — is stored in India. We do not replicate to other regions.
Compliance posture — honestly
We will never overstate where we are. Here is where we actually stand on the frameworks customers ask about.
Roles, breach notification, data subject rights, retention all modelled on DPDP requirements. Sample DPA available — contact us.
Targeting Q4 2026 via Vanta. We can share security questionnaire responses today.
TheraFlow operates in India; HIPAA is a US framework. We do not market HIPAA compliance.
Targeted post-SOC 2. We adopt ISO controls as we mature.
Security controls in place today
The technical and operational controls that are live and audited internally.
- Role-based access control (admin, manager, therapist, receptionist, guardian)
- Mandatory MFA available for all staff accounts (Clerk-backed)
- Strict password policy + rate-limited login + account lockout
- Server-side input validation on every endpoint (Zod schemas)
- All write operations are tenant-scoped at the query layer
- Audit log of every record access and mutation
- Per-feature kill switches — disable risky features per centre without a code release
- No customer PII in application logs
- Vulnerability scanning on every build
- Quarterly access review of internal staff who touch production
Documents & legal
Everything a careful customer's CA or legal advisor will ask for.
Frequently asked
Who can see our patient data inside TheraFlow?
Only your centre's staff — based on the role you grant them. On our side, access to production data is restricted to a small set of named engineers, requires MFA, and every access is logged. We never view patient records casually; access happens only for explicit support tickets you raise.
Do you sell or share our data with anyone?
No. We never sell or share patient data. We use named sub-processors (AWS, Clerk, Anthropic, Razorpay) strictly to operate the service. The full list is on our sub-processors page.
Will your AI features train on our patients' data?
No. Our AI features call Anthropic and Google APIs with no-training settings, which is the API default. No customer data is used to train any model — ours or theirs.
What happens to our data if we cancel?
You get 60 days to export everything (one-click export). After 60 days, your tenant is irreversibly deleted from primary storage and removed from all backups within the next 60 days.
Can we sign a Data Processing Agreement (DPA)?
Yes. We have a DPA modelled on DPDP Act 2023 ready to sign. Email founders@theraflow.in and we will send the current version for your review.
Will you keep our files on our own Google Drive?
Coming soon. We are building an integration that lets your centre connect its own Google Drive — large files (intake forms, reports, photos) live in your Drive, with TheraFlow holding only the reference. Your most sensitive documents stay on infrastructure you already control.
Are you SOC 2 certified?
Not yet — we are early stage and honest about that. SOC 2 Type 1 is on the roadmap for Q4 2026. We are happy to fill out your security questionnaire today.
Who do I contact for a security or privacy question?
founders@theraflow.in. Real humans, not a ticket queue. We respond within one business day.
Security questionnaire? DPA? Pen test report request?
Send it to founders@theraflow.in. A founder replies — usually within one business day.
Email founders