Home / Security & Compliance
Data Governance

Enterprise trust,
engineered for clinical data.

Medical intelligence requires zero-trust architecture, strict data sovereignty, and verifiable clinical governance. Curota Health is built to bridge high-throughput healthcare AI pipelines and the strictest global data protection mandates — while drawing a clear line between our own controls and the infrastructure certifications supplied by technology partners.

The Curota Trust & Security Matrix

The pillars of clinical data safety.

Three reinforcing domains — how data is governed, how the infrastructure is engineered, and how the people who touch clinical data are controlled.

01

Data Governance & Privacy Controls

We process clinical data without asserting ownership over client IP or sensitive PHI.

  • Zero-persistence data streaming — options for zero-data-retention, where datasets are processed in-memory and flushed immediately post-annotation.
  • Granular RBAC — role-based access limited by clinical specialty, project assignment, and least-privilege principles.
  • De-identification pipelines — automated plus double-pass human verification to strip direct identifiers, designed against HIPAA Safe Harbor and Expert Determination methods.
  • Immutable audit logs — every view, label change, expert escalation, and export traceable by reviewer ID and timestamp.
02

Infrastructure & Cyber Security

Engineered for memory safety, data integrity, and zero-trust cloud deployment.

  • Memory-safe systems architecture — systems programming (Rust / modern C++) to prevent buffer overflows and data leakage when parsing complex DICOM and whole-slide imaging datasets.
  • Image provenance & tamper-proofing — digital watermarking and cryptographic hashing so clinical metadata and AI annotation layers remain verifiably unaltered.
  • Encryption standards — AES-256 at rest and TLS 1.3 in transit, per project architecture and contractual requirements.
  • Client in-situ deployment — reviewers work directly inside the client's AWS HealthLake, Azure, or GCP environment. Data never leaves your perimeter.
  • Curota-hosted deployment — isolated Virtual Private Clouds provisioned on enterprise infrastructure providers that maintain SOC 2 Type II and ISO 27001 certified environments.
03

Workforce & Clinical Safety

Enterprise security ultimately depends on the people interacting with the data.

  • Verified credentialing — multi-step licence verification and background vetting for board-certified physicians, specialists, and clinical annotators.
  • Clean-room workspace protocols — screen-capture prevention, disabled local storage, and physical clean-room policies for high-sensitivity visual datasets.
  • Mandatory training — annual workforce training covering HIPAA, GDPR, India's DPDP Act, and clinical research ethics.
  • Structural independence — specialty sign-off protected from commercial and throughput pressure, as set out in our governance framework.
Our Controls

Confidentiality, controlled access, and traceability by default.

Data confidentiality

NDA-controlled engagement and workforce confidentiality obligations across every project.

Role-based access

Least-privilege principles with access segregated by project and jurisdiction.

Secure environments

Controlled, project-specific data environments with access approvals.

Encryption

Encryption in transit and at rest, per project architecture and contractual requirements.

Audit trails

Comprehensive audit logging so critical actions remain traceable.

Data retention

Defined retention policies and controlled data-access lifecycles.

Incident escalation

Defined incident-escalation pathways and response responsibilities.

Vendor governance

Controls extended to ecosystem partners through vendor-governance requirements.

Regional handling

Jurisdiction-aware processing and explicit cross-border transfer mechanics where applicable.

Global & Regional Compliance Enablers

Cross-border compliance, without compromise.

Curota Health is structured to act as a compliant data processor and clinical validation partner across major global jurisdictions. We enable our clients' compliance obligations — we are not a regulatory authority and do not issue regulatory approval.

IN

India Data Standards

  • DPDP Act (2023) — designed to operate as a Data Processor, with purpose limitation, verifiable consent tracking, and localized edge processing.
  • ABDM & HDM Policy — aligned to Ayushman Bharat Digital Mission health data management policy, with secure payload encryption for ABHA-linked records.
  • MoHFW Telemedicine Guidelines — aligned to Ministry of Health EHR standards for clinical data capture and audit-retention rules.
  • CERT-In cybersecurity directions — incident response structured around the mandated 6-hour cyber incident reporting timeline and NTP-synchronised forensic logging.
US

United States

  • HIPAA / HITECH — structured to execute Business Associate Agreements and to operate under the Security and Privacy Rules where a BAA is in place.
  • FDA GMLP — supports Good Machine Learning Practice by delivering independent, traceability-audited validation and bias-testing datasets. Curota Health does not perform regulatory clearance or submission.
EU

European Union & Global

  • EU AI Act & CE-MDR — produces the traceable, human-in-the-loop evaluation evidence packages that high-risk clinical AI deployments require of their operators.
  • GDPR — data minimisation and cross-border transfer handled through Standard Contractual Clauses.
  • ISO/IEC 27001 & 27701 — operational security and privacy controls aligned to these international frameworks.
Compliance note: Curota Health deploys client projects using enterprise infrastructure providers that maintain SOC 2 Type II, ISO 27001, and HIPAA-compliant environments, subject to specific project architecture and contractual requirements. Alignment to a framework is not the same as certification against it. No certification is presented as held by the Curota Health entity unless formally verified and directly applicable.
Cross-Border Data Governance Pipeline

Follow-the-sun delivery.
Sovereign data protection.

Indian clinical reviewers and domain experts work directly inside the client's localized environment via secure zero-trust streaming — so the data never leaves the client's geographical border.

01
Client Cloud VPC
US · EU · India. Data stays resident in the client's own environment and jurisdiction.
02
Zero-Persistence View Port
TLS 1.3 secure streaming session. Nothing is written to reviewer-side storage.
03
Global Specialist Bench
Remote clinical review and adjudication only — no download, no local copy.
04
Immutable Edge Audit Log
Every action logged by reviewer ID and timestamp, back to the client's audit trail.
Core principle: review travels to the data; the data does not travel to the reviewer. Specific residency, streaming, and logging architecture is set per engagement and confirmed contractually.
Cybersecurity & Technical Advisory

Guided by deep systems expertise.

Curota Health's infrastructure and security protocols are shaped by specialised technical advisors working alongside the engineering team.

Kamal Kumar, Technical Advisor — Systems Architecture & Data Security at Curota Health
Kamal Kumar
Technical Advisor — Systems Architecture & Data Security
Founder, Apt Computing Labs · M.Tech (Image Processing), NIT Rourkela

Kamal advises Curota Health on building memory-safe data ingestion pipelines, image provenance — watermarking and tamper-proofing for DICOM and whole-slide imaging — and zero-trust infrastructure environments for processing high-volume clinical datasets.

Focus areas: Memory-safe systems programming (Rust) · Digital image processing integrity · Embedded systems · Edge AI security.
Advisory scope: Technical advisory only — no clinical sign-off authority and no access to case-level clinical decisions.
Incident Response & Disclosure

Proactive security operations.

Continuous monitoring

Intrusion detection and data-loss-prevention controls across operational networks.

Rapid incident escalation

SLA-bound response workflows to notify clients, CERT-In, and relevant health authorities within mandated timeframes.

Responsible disclosure

A responsible-disclosure channel for security researchers to report findings against the clinical intelligence layer.

An Important Distinction

We never inherit a partner's certification.

Curota Health clearly distinguishes between its own controls and the infrastructure or security capabilities supplied by technology partners. Marketing language must reflect that line.

✕ Incorrect

"Curota Health is SOC 2 Type II Certified" — when only an infrastructure partner holds that certification.

✓ Correct

"Projects may be deployed using infrastructure providers maintaining applicable enterprise security certifications, subject to project architecture and contractual requirements."

NDA-controlled engagement RBAC · least-privilege Encryption in transit & at rest Audit logging Partner-held infra certifications → Jurisdiction-specific frameworks →
Certifications, regulatory statements, and compliance claims are intended to be CMS-controlled and verified before publication. No certification is presented as held by the Curota Health entity unless formally verified and directly applicable. Confirm current status with Curota Health before relying on any specific certification or regulatory claim.

Your technology has intelligence.
Give it clinical intelligence.

Talk to Curota Health