Skip to content
SOTTO

Security & compliance

SOTTO handles medical information, so security comes before convenience.

Encryption

All connections use TLS. Account data and backups are encrypted at rest.

Secure sign-in

The desktop app signs in through your normal browser using OAuth with PKCE. Passwords are never typed into the app, and admins must use a second factor.

Role-based access

Owners, admins, doctors and receptionists each see only what their role allows. Every permission is checked on our servers, not just in the app.

Audit logs

Sign-ins and access to patient records are logged: who, what and when.

Lost device protection

Sign out any device remotely from your account. Short-lived access means a lost laptop loses access within minutes.

Backup & monitoring

Essential data is backed up to more than one cloud and our services are monitored around the clock.

No patient data on this website

This website only handles your account and billing. Patient records stay in the SOTTO app.

Compliance

We are building SOTTO to meet India's Digital Personal Data Protection Act, 2023 and its Rules. We list certifications here only once they are complete.

  • Digital Personal Data Protection Act, 2023In progress
  • ABDM guidelines (if ABHA integration is enabled)In progress
  • CERT-In incident reporting directionsIn progress

Report a security issue

Found a vulnerability? Please e-mail security@sottohealth.com. We respond to every report and ask that you give us time to fix issues before disclosing them.

security@sottohealth.com