VaniOS← Home
Trust register · v1.0 · Updated 2026

The promises we make to every doctor and every patient.

VaniOS handles consultations, prescriptions, and health data. Trust is the product. Below is exactly where data lives, who can see it, and what we will never do with it.

01
Patient data stays in India.

Your patients' notes, prescriptions, and audio recordings are stored in Mumbai (ap-south-1). They never leave Indian jurisdiction. Backups are also in-region.

02
We never train AI on your patients.

Lovable AI Gateway and our SOMA model providers are contractually configured for zero-retention. Your transcripts and notes are not used to train any model — ours or anyone else's.

03
DPDP Act 2023 ready by design.

Verbal patient consent is captured and timestamped before recording (or recording cannot start). Every access is written to an immutable audit log. Patients have a right to deletion on request.

04
ABDM-shaped exports, on demand.

Every consultation can be exported as an ABDM-compatible FHIR R4 bundle in one tap. Your patients can carry their record to any clinic that speaks ABDM.

05
Row-level security, end to end.

A doctor sees their own patients. A clinic member sees the clinic's patients. A nurse cannot edit signed prescriptions. These rules are enforced in the database, not just the UI — even if our code has a bug.

06
Encrypted in transit and at rest.

TLS 1.3 in transit. AES-256 at rest. Audio recordings are deleted from temporary processing buckets within 24 hours of transcription.

07
You own your data. Always.

Export everything as JSON or FHIR bundle from Settings. Cancel any time and we delete your records within 30 days. No lock-in. No 'your data is in our format now' games.

Disclosures

Found something? Tell us, not the internet.

Responsible security disclosure: security@vanios.com. We respond within 24 hours and credit researchers in our public advisory.

Privacy questions / DPDP requests: privacy@vanios.com.

Compliance roster
Sign your first consultation →