Security & Privacy at DrGuru.ai

DrGuru.ai is built as a secure, consent-based smart health report platform. Patient reports sit behind verified access, private infrastructure, role-based permissions, MFA/2FA for privileged users, audit logs, and responsible AI safeguards.

Last updated: August 5, 2026

India-region hosting

Primary application server and database are hosted on DigitalOcean infrastructure in Bangalore, India.

OTP verified access

Patients open dashboards through secure links and OTP verification, not open public report pages.

MFA / 2FA controls

Admin, lab, doctor and hospital partner accounts are protected through MFA/2FA policies for production use.

Private by design

Raw reports, databases and health dashboards are not exposed as public files or public database endpoints.

Direct Answer

No digital health platform can honestly claim zero risk. DrGuru.ai reduces risk through layered controls: verified access, limited exposure, role-based permissions, consent-based processing, safe notification channels, audit logging, and restricted operational access.

What we do: process reports for smart dashboard creation, secure sharing, reminders, care continuity, support and security.
What we do not do: sell patient health data, publish raw reports on public URLs, or use AI as a replacement for doctor diagnosis or treatment decisions.

Infrastructure & Data Protection

  • Application hosting: Primary app server runs in DigitalOcean's Bangalore, India region. Public access is limited to secure web application endpoints.
  • Private database: Production database access is restricted to application/backend and approved admin channels.
  • Private reports: PDFs/images are accessed through authenticated or OTP-verified flows, signed links, or controlled streaming.
  • Transport security: HTTPS/TLS protects app traffic.
  • Encryption controls: Managed database/storage services are configured for provider-supported encryption controls.
  • Secrets handling: Database credentials, API keys and OTP/WhatsApp credentials live outside code in environment/configuration management.
  • Backups: Production backups are restricted and protected, with restore checks planned for hospital-grade continuity.

Access Control

  • Patients: view their own verified dashboard, reports, trends and health timeline.
  • Family managers: manage family member profiles only when created or authorized under their account.
  • Doctors: view only patients/reports shared with them or assigned through a lab/hospital workflow.
  • Labs: upload/process reports and view only reports connected to their account or authorized workflow.
  • Hospital admins: access operational dashboards configured under the partner agreement; patient-level access is role and purpose controlled.
  • Support/admin: restricted access only for support, security, processing and operations; sensitive actions are logged.

Verification & Audit

  • Patient OTP: secure dashboard links require OTP verification to reduce accidental access if a link is forwarded.
  • MFA/2FA: privileged production accounts for admins, hospitals, labs and doctors are protected with multi-factor controls.
  • Session protection: sessions are time-limited and inactive sessions can expire; sensitive actions can require fresh verification.
  • Audit logs: upload, processing, OTP verification, view, share, doctor access, lab access, admin action and deletion requests can be traced.

Safe Communication

  • • WhatsApp/SMS are used for notification and secure access, not for exposing full lab values or report details in an open message thread.
  • • Patient notifications point to an OTP-protected verification flow.
  • • Doctor notifications depend on the authorized lab/hospital workflow and lead to controlled access.
  • • Views and shares are logged to support accountability for hospital and lab partners.

Responsible AI

  • • AI extracts report values, dates, ranges and abnormal markers into structured form.
  • • AI explanations use plain language with doctor-consultation guidance.
  • • AI output is not final diagnosis, prescription or treatment. Doctors remain responsible for medical decisions.
  • • Original reports remain available so doctors can verify source data.
  • • Only necessary report information is processed for extraction, explanation and dashboard generation.
  • • Patient reports are not used by DrGuru.ai for unrelated model training or resale without explicit consent.
  • • Low-confidence extraction or unclear formatting can be flagged for review before relying on structured output.

Operations & Assurance

  • Retention: reports are retained for dashboard continuity unless deletion is requested or partner policy requires a defined window.
  • Incident response: contain, investigate, fix, document and notify affected parties as legally required.
  • Vendor review: security questionnaire responses, partner agreement, privacy policy, DPA and subprocessor list can be provided during onboarding.
  • Enterprise options: secure API, SFTP, whitelisted IPs, VPN/private networking and dedicated tenant-level separation can be considered for hospital IT policy.

Responsible Disclosure

If you believe you’ve found a vulnerability, please email [email protected]. Don’t test against real patient data. We’ll acknowledge and work with you to remediate.

Compliance Position

  • • DrGuru.ai controls are aligned to privacy-by-design principles, India's DPDP framework expectations, and ABDM-style consent/privacy thinking.
  • • This page does not claim ISO 27001, HIPAA, ABDM, or other formal regulatory certification.
  • • Detailed technical review, DPA and security questionnaire responses can be provided during hospital/vendor onboarding.

Contact

Security questions? Reach us at [email protected].