Privacy Commitment

What happens in
your clinic, stays
in your clinic.

Patient records are the most sensitive data in the world. We built CuraVerto so they never leave your control — not to advertisers, not to third parties, not even to us unless you ask.

Our Promise

Four things we promise.

01

Your data is never sold

We have no ad business. No data-sharing partnerships. No revenue model that touches your patient records. Our only customer is you.

02

Data stays in India

All patient data lives on servers in Mumbai. No cross-border transfers for clinical data — ever. Indian servers for Indian clinics.

03

We only access your data when you ask

Support access requires your explicit consent and is fully logged. We cannot enter your records without your knowledge.

04

You can leave — with everything

Full data export in standard formats at any time. No lock-in. No data held hostage after you cancel.

For the technical team

Encryption

AT REST
AES-256-GCM
IN TRANSIT
TLS 1.3
BACKUPS
Encrypted before leaving the server

Access Control

ROLES
8 clinical roles + internal roles
SESSIONS
JWT-verified, time-limited
AUDIT
Every write logged — who, what, when

DPDP Act 2023

CONSENT
Explicit and documented per patient
DELETION
Data deletion requests are honoured
ISOLATION
No cross-clinic data aggregation
Enterprise

For hospitals that need complete isolation.

On our shared cloud, your data is already siloed at the application layer. But some hospitals need more — a server that's entirely theirs. CuraVerto's Private VPC gives you a dedicated environment: your own database, your own encryption key (BYOK), your own infrastructure. No shared resources. No shared risk.

Single-tenant databaseBYOK — your encryption keyCustom API access
Talk to us about Enterprise

Questions about how we handle your data?

We'll give you a straight answer — no sales pitch.

Chat with us on WhatsAppRead our Privacy Policy