Platform security & governance
All systems operational
Diabeasy Platform Settings
MFA enforcement
100%
All 1,247 users · enforced policy
Password compliance
98.4%
21 users due rotation in 7d
Failed logins · 24h
12
2 accounts auto-locked
Vulnerabilities
0critical
Last scan: 11 May 03:00 IST
Security
🔐 Authentication policy
🏢 SSO per tenant
👥 Role definitions
🔑 API keys & webhooks
🛡 Encryption & KMS
Data & compliance
🌐 Data residency
📅 Retention policies
📜 Certifications
🔓 DPDP register
Operations
⚙ System health
💾 Backup & DR
📊 Observability
🚨 Incident response
Authentication policy
Applies platform-wide · individual tenants may layer stricter rules
MFAWhether multi-factor is required
Enforce MFA for all human usersMandatory · cannot be disabled per DPDP / ISO 27001 controls
policy-locked
TOTP authenticator (primary)Google Authenticator, 1Password, Authy
on
SMS OTP (fallback only)Allowed when TOTP unavailable; not as primary
on
Hardware key (WebAuthn / FIDO2)Recommended for privileged roles (admin, PV reviewer)
on
Password policy
| Minimum length | 14 characters |
| Complexity | upper + lower + digit + symbol |
| Rotation interval | 180 days |
| Reuse prevention | last 12 passwords |
| Breach check (HIBP API) | on every set |
| Failed-attempt lockout | 5 attempts · 15 min cool-down |
Session timeouts
| Doctor portal | 4h idle · 12h absolute |
| Coach console | shift-bound · max 9h |
| Pharma sponsor portal | 2h idle · 8h absolute |
| Admin / super-admin | 30 min idle · 4h absolute · re-MFA on sensitive ops |
| Patient mobile app | 7d remember · biometric unlock |
SSO configuration per tenant
Each sponsor connects their corporate IdP for their employees
N
Novo Nordisk India
Microsoft Entra ID
✓ Healthy
L
Lupin Limited
Okta
✓ Healthy
S
Sanofi India
Microsoft Entra ID
⌛ Cert rotation due in 18d
U
USV Private Limited
Auth0
✓ Healthy
D
Caresoft / Diabeasy internal
Google Workspace
✓ Healthy
Role definitions & permissions
Per-role capability matrix · principle of least privilege
| Capability | Doctor | Coach | Sr. Coach | Pharma BM | PV Reviewer | Tenant Admin | Super-admin |
|---|---|---|---|---|---|---|---|
| Read patient PHI | ● | ● | ● | ○ | ● | ○ | ● |
| Read patient aggregate / de-id | ● | ● | ● | ● | ● | ● | ● |
| Enrol patient into PSP | ● | ○ | ○ | ○ | ○ | ○ | ● |
| Edit prescription | ● | ○ | ○ | ○ | ○ | ○ | ○ |
| Make coach call · log disposition | ○ | ● | ● | ○ | ○ | ○ | ○ |
| File AE report | ● | ● | ● | ○ | ● | ○ | ● |
| Sign clinical narrative on AE | ● | ○ | ○ | ○ | ● | ○ | ○ |
| Export cohort (de-id only) | ○ | ○ | ○ | ● | ◐ | ● | ● |
| Configure programme | ○ | ○ | ○ | ○ | ○ | ● | ● |
| Manage users in tenant | ○ | ○ | ○ | ○ | ○ | ● | ● |
| Platform settings & SSO | ○ | ○ | ○ | ○ | ○ | ○ | ● |
| Read audit logs | ◐ | ◐ | ◐ | ◐ | ◐ | ● | ● |
Legend:
● Full ·
◐ Scoped (own actions / tenant only) ·
○ Denied
API keys & webhooks
Machine-to-machine integrations · auto-rotated every 90 days
1mg fulfilment · production
Novo Nordisk safety database · CIOMS push
Thyrocare lab orders
Karix WhatsApp Business API
Knowlarity voice (coach VoIP)
RWE Data Vault export (Novo Premium tier)
Compliance certifications
External audits passed · last reviewed by procurement reviewers
ISO
ISO 27001:2022
Information security management system
Auditor
BSI India
Cert no.
IS-784292
Issued
14 Mar 2026
Expires
14 Mar 2029
✓ Active · annual surveillance Feb 2027
SOC
SOC 2 Type II
Trust services criteria · security, availability, confidentiality
Auditor
Deloitte
Period
12 mo · 2025
Issued
22 Jan 2026
Renewal
Jan 2027
✓ No material exceptions
DPDP
DPDP Act 2023
India personal-data protection compliance
DPO
Aarushi N.
Reg ID
DPDP-DF-9482
Filed
02 Feb 2026
Next review
Feb 2027
✓ Significant data fiduciary tier
HI
HIPAA aligned
For US tele-consult partner integrations
Attestation
self · annual
Reviewer
Drata
Last review
02 Mar 2026
BAAs
3 active
✓ Aligned (not certified)
GCP
GxP / GCP-aligned
For RWE Data Vault & regulatory submissions
Framework
21 CFR Part 11
CSV evidence
complete
Validated
18 Apr 2026
Audit log
WORM · 7-yr
✓ Validation pack available
CB
CERT-In empanelled audit
India CERT-In cybersecurity audit certification
Auditor
SISA
Type
Pen-test + VAPT
Last test
28 Apr 2026
Findings
0 critical · 2 low
✓ Empanelled certificate available
System health · live
Real-time service status · 30-day uptime
Web app · doctor / coach / pharma / admin portals
Mobile API · patient app v3.4
PostgreSQL primary · ap-south-1a
Thyrocare lab integration
Novo PV API · CIOMS forwarding
Audit log stream · WORM S3
Backups · 15-min RPO