Security & compliance
SOTTO handles medical information, so security comes before convenience.
Encryption
All connections use TLS. Account data and backups are encrypted at rest.
Secure sign-in
The desktop app signs in through your normal browser using OAuth with PKCE. Passwords are never typed into the app, and admins must use a second factor.
Role-based access
Owners, admins, doctors and receptionists each see only what their role allows. Every permission is checked on our servers, not just in the app.
Audit logs
Sign-ins and access to patient records are logged: who, what and when.
Lost device protection
Sign out any device remotely from your account. Short-lived access means a lost laptop loses access within minutes.
Backup & monitoring
Essential data is backed up to more than one cloud and our services are monitored around the clock.
No patient data on this website
This website only handles your account and billing. Patient records stay in the SOTTO app.
Compliance
We are building SOTTO to meet India's Digital Personal Data Protection Act, 2023 and its Rules. We list certifications here only once they are complete.
- Digital Personal Data Protection Act, 2023In progress
- ABDM guidelines (if ABHA integration is enabled)In progress
- CERT-In incident reporting directionsIn progress
Report a security issue
Found a vulnerability? Please e-mail security@sottohealth.com. We respond to every report and ask that you give us time to fix issues before disclosing them.
security@sottohealth.com