Your patient data, on your terms.
Therapy centres handle some of the most sensitive data in healthcare — children's names, diagnoses, parent contacts. We've built TheraFlow so you stay in control of that data, can audit what we touch, and can take everything with you anytime.
Last reviewed 7 June 2026
We hold the minimum
Many fields (Aadhaar, ABHA ID, full address, medical history) are optional. Skip them and we never store them. You decide what enters the system.
Encrypted everywhere
AES-256 encryption at rest (AWS RDS) and TLS 1.3 in transit. No customer data ever leaves the encrypted boundary in plain text.
Strict per-tenant isolation
Every database query is filtered by your centre's tenant_id. Our application layer cannot return another centre's data even by mistake.
AI features are opt-in
Scheduling AI, report generation, and clinical reasoning are off by default. You turn them on per feature, knowing exactly when data flows to an LLM. Anthropic and Google do not train on our API calls.
You can see what we touched
Per-centre activity log: who accessed which patient record, when, from where. Available to admins from Settings.
Take everything, anytime
One-click export of every patient, appointment, note, and invoice as JSON/CSV. If you ever leave, you leave with all your data.
Delete on your terms
Wipe a single patient or your entire centre. 30-day grace period to restore, then irreversible deletion across all backups within 60 days.
Breach notification — 72 hours
If we ever discover a security incident affecting your data, you and India's Data Protection Board are notified within 72 hours, with everything we know.
Where your data lives
All customer data — primary, backups, files, email — is stored in India. We do not replicate to other regions.
Compliance posture — honestly
We will never overstate where we are. Here is where we actually stand on the frameworks customers ask about.
Roles, breach notification, data subject rights, retention all modelled on DPDP requirements. Sample DPA available — contact us.
Targeting Q4 2026 via Vanta. We can share security questionnaire responses today.
TheraFlow operates in India; HIPAA is a US framework. We do not market HIPAA compliance.
Targeted post-SOC 2. We adopt ISO controls as we mature.
Security controls in place today
The technical and operational controls that are live and audited internally.
- Role-based access control (admin, manager, therapist, receptionist, guardian)
- Mandatory MFA available for all staff accounts (Clerk-backed)
- Strict password policy + rate-limited login + account lockout
- Server-side input validation on every endpoint (Zod schemas)
- All write operations are tenant-scoped at the query layer
- Audit log of every record access and mutation
- Per-feature kill switches — disable risky features per centre without a code release
- No customer PII in application logs
- Vulnerability scanning on every build
- Quarterly access review of internal staff who touch production
Documents & legal
Everything a careful customer's CA or legal advisor will ask for.
Frequently asked
Security questionnaire? DPA? Pen test report request?
Send it to founders@theraflow.in. A founder replies — usually within one business day.
Email founders