Home / Security & Compliance
Data Governance

Enterprise trust,
engineered for clinical data.

Medical intelligence requires zero-trust architecture, strict data sovereignty, and verifiable clinical governance. Curota Health is built to bridge high-throughput healthcare AI pipelines and the strictest global data protection mandates — while drawing a clear line between our own controls and the infrastructure certifications supplied by technology partners.

The Curota Trust & Security Matrix

The pillars of clinical data safety.

Three reinforcing domains — how data is governed, how the infrastructure is engineered, and how the people who touch clinical data are controlled.

01

Data Governance & Privacy Controls

We process clinical data without asserting ownership over client IP or sensitive PHI.

  • Zero-persistence data streaming — options for zero-data-retention, where datasets are processed in-memory and flushed immediately post-annotation.
  • Granular RBAC — role-based access limited by clinical specialty, project assignment, and least-privilege principles.
  • De-identification pipelines — automated plus double-pass human verification to strip direct identifiers, designed against HIPAA Safe Harbor and Expert Determination methods.
  • Immutable audit logs — every view, label change, expert escalation, and export traceable by reviewer ID and timestamp.
02

Infrastructure & Cyber Security

Engineered for memory safety, data integrity, and zero-trust cloud deployment.

  • Memory-safe systems architecture — systems programming (Rust / modern C++) to prevent buffer overflows and data leakage when parsing complex DICOM and whole-slide imaging datasets.
  • Image provenance & tamper-proofing — digital watermarking and cryptographic hashing so clinical metadata and AI annotation layers remain verifiably unaltered.
  • Encryption standards — AES-256 at rest and TLS 1.3 in transit, per project architecture and contractual requirements.
  • Client in-situ deployment — reviewers work directly inside the client's AWS HealthLake, Azure, or GCP environment. Data never leaves your perimeter.
  • Curota-hosted deployment — isolated Virtual Private Clouds provisioned on enterprise infrastructure providers that maintain SOC 2 Type II and ISO 27001 certified environments.
03

Workforce & Clinical Safety

Enterprise security ultimately depends on the people interacting with the data.

  • Verified credentialing — multi-step licence verification and background vetting for board-certified physicians, specialists, and clinical annotators.
  • Clean-room workspace protocols — screen-capture prevention, disabled local storage, and physical clean-room policies for high-sensitivity visual datasets.
  • Mandatory training — annual workforce training covering HIPAA, GDPR, India's DPDP Act, and clinical research ethics.
  • Structural independence — specialty sign-off protected from commercial and throughput pressure, as set out in our governance framework.
Our Controls

Confidentiality, controlled access, and traceability by default.

Data confidentiality

NDA-controlled engagement and workforce confidentiality obligations across every project.

Role-based access

Least-privilege principles with access segregated by project and jurisdiction.

Secure environments

Controlled, project-specific data environments with access approvals.

Encryption

Encryption in transit and at rest, per project architecture and contractual requirements.

Audit trails

Comprehensive audit logging so critical actions remain traceable.

Data retention

Defined retention policies and controlled data-access lifecycles.

Incident escalation

Defined incident-escalation pathways and response responsibilities.

Vendor governance

Controls extended to ecosystem partners through vendor-governance requirements.

Regional handling

Jurisdiction-aware processing and explicit cross-border transfer mechanics where applicable.

Global & Regional Compliance Enablers

Cross-border compliance, without compromise.

Curota Health is structured to act as a compliant data processor and clinical validation partner across major global jurisdictions. We enable our clients' compliance obligations — we are not a regulatory authority and do not issue regulatory approval.

IN

India Data Standards

  • DPDP Act (2023) — designed to operate as a Data Processor, with purpose limitation, verifiable consent tracking, and localized edge processing.
  • ABDM & HDM Policy — aligned to Ayushman Bharat Digital Mission health data management policy, with secure payload encryption for ABHA-linked records.
  • MoHFW Telemedicine Guidelines — aligned to Ministry of Health EHR standards for clinical data capture and audit-retention rules.
  • CERT-In cybersecurity directions — incident response structured around the mandated 6-hour cyber incident reporting timeline and NTP-synchronised forensic logging.
US

United States

  • HIPAA / HITECH — structured to execute Business Associate Agreements and to operate under the Security and Privacy Rules where a BAA is in place.
  • FDA GMLP — supports Good Machine Learning Practice by delivering independent, traceability-audited validation and bias-testing datasets. Curota Health does not perform regulatory clearance or submission.
EU

European Union & Global

  • EU AI Act & CE-MDR — produces the traceable, human-in-the-loop evaluation evidence packages that high-risk clinical AI deployments require of their operators.
  • GDPR — data minimisation and cross-border transfer handled through Standard Contractual Clauses.
  • ISO/IEC 27001 & 27701 — operational security and privacy controls aligned to these international frameworks.
Cross-Border Data Governance Pipeline

Follow-the-sun delivery.
Sovereign data protection.

Indian clinical reviewers and domain experts work directly inside the client's localized environment via secure zero-trust streaming — so the data never leaves the client's geographical border.

01
Client Cloud VPC
US · EU · India. Data stays resident in the client's own environment and jurisdiction.
02
Zero-Persistence View Port
TLS 1.3 secure streaming session. Nothing is written to reviewer-side storage.
03
Global Specialist Bench
Remote clinical review and adjudication only — no download, no local copy.
04
Immutable Edge Audit Log
Every action logged by reviewer ID and timestamp, back to the client's audit trail.
Core principle: review travels to the data; the data does not travel to the reviewer. Specific residency, streaming, and logging architecture is set per engagement and confirmed contractually.
Cybersecurity & Technical Advisory

Guided by deep systems expertise.

Curota Health's infrastructure, security protocols and privacy frameworks are shaped by specialised advisors working alongside the engineering team.

Kamal Kumar, Technical Advisor — Systems Architecture & Data Security at Curota Health
Kamal Kumar
Technical Advisor — Systems Architecture & Data Security
Founder, Apt Computing Labs · M.Tech (Image Processing), NIT Rourkela

Kamal advises Curota Health on building memory-safe data ingestion pipelines, image provenance — watermarking and tamper-proofing for DICOM and whole-slide imaging — and zero-trust infrastructure environments for processing high-volume clinical datasets.

Focus areas: Memory-safe systems programming (Rust) · Digital image processing integrity · Embedded systems · Edge AI security.
M Dinesh Kumar, Lead — Data Privacy & AI Governance at Curota Health
M Dinesh Kumar
Lead — Data Privacy & AI Governance
LLM Candidate (IT & Data Privacy), Manipal Law School · BA LLB

Dinesh runs legal compliance and data protection. His field is IT law, AI governance and data privacy regulation — India's DPDP Act and the GDPR in particular — and his job is making sure our validation pipelines and cross-border workflows actually meet those statutes. He also handles the digital contracts and regulatory analysis enterprise clients lean on when they have to show their AI work is compliant.

Focus areas: IT law · AI governance · DPDP Act & GDPR compliance · Cross-border data transfer · Digital contracts & regulatory analysis.
Incident Response & Disclosure

Proactive security operations.

Continuous monitoring

Intrusion detection and data-loss-prevention controls across operational networks.

Rapid incident escalation

SLA-bound response workflows to notify clients, CERT-In, and relevant health authorities within mandated timeframes.

Responsible disclosure

A responsible-disclosure channel for security researchers to report findings against the clinical intelligence layer.

An Important Distinction

We never inherit a partner's certification.

Curota Health clearly distinguishes between its own controls and the infrastructure or security capabilities supplied by technology partners. Marketing language must reflect that line.

✕ Incorrect

"Curota Health is SOC 2 Type II Certified" — when only an infrastructure partner holds that certification.

✓ Correct

"Projects may be deployed using infrastructure providers maintaining applicable enterprise security certifications, subject to project architecture and contractual requirements."

NDA-controlled engagement RBAC · least-privilege Encryption in transit & at rest Audit logging Partner-held infra certifications → Jurisdiction-specific frameworks →

Your technology has intelligence.
Give it clinical intelligence.

Talk to Curota Health