Skip to content
Regulatory Compliance

Compliance is our moat.

Indian healthcare is one of the most regulated sectors in the world. Nexura OS is built compliant from the architecture up — not as a feature, but as a principle.

ABDM

Ayushman Bharat Digital Mission

In Progress

India's national digital health mission. Mandates ABHA ID, health record exchange, and ABDM-compliant APIs.

Certification target: Q1 2026

What we've built

ABHA ID generation + lookup
Health Information Exchange (HIE)
Consent manager integration
ABDM-compliant API endpoints
Health record linking across providers

DPDP 2023

Digital Personal Data Protection Act

Built-in

India's data privacy law. Requires patient consent, data localization, breach notification, and right to erasure.

Alignment tracked since launch

What we've built

Explicit patient consent flow
Single-region deployment; India-region hosting planned
Right to erasure (self-serve in Foresight; clinic-desk assisted)
Hash-chained, tamper-evident audit trail
Breach-response playbook; automated detection planned
Data-retention engine with configurable purge profiles

NABH

National Accreditation Board for Hospitals

Standards-ready

Voluntary accreditation for hospitals. Nexura OS tracks all NABH quality indicators.

Audit-ready: Q2 2026

What we've built

Patient safety indicators
Infection control tracking
Medication error logging
Quality indicator dashboards
NABH audit-ready reports
Continuous quality monitoring

CDSCO

Central Drugs Standard Control Organisation

Built-in

Regulates drugs, medical devices, and clinical trials. Schedule H/H1 drug tracking mandatory.

Alignment tracked since launch

What we've built

Schedule H / H1 drug register
Drug traceability (barcodes)
Prescription validation
Pharmacovigilance reporting
Batch + expiry tracking (FEFO)
CDSCO audit export (CSV)

IRDAI

Insurance Regulatory and Development Authority

Built-in

Regulates insurance. Cashless pre-auth + TPA claims workflow per IRDAI guidelines.

Alignment tracked since launch

What we've built

TPA pre-authorization workflow
Cashless claim submission
Claim status tracking
Co-pay + deductible calculation
Discharge summary generation
IRDAI-compliant claim format

GST e-Invoice

Goods and Services Tax e-Invoice

Built-in

Mandatory GST e-invoice for B2B transactions >₹50,000. IRN-ready JSON + e-way bill.

Alignment tracked since launch

What we've built

IRN-ready JSON generation
CGST + SGST split (correct slabs)
HSN code mapping
E-way bill generation (auto)
State code mapping (all 28 states)
GST return export

Architecture principles

Encryption in transit

TLS/HTTPS for all traffic today. At-rest encryption is on the roadmap and not yet enabled on the current database.

Tamper-evident audit trail

Every API action is logged with timestamp, user, and role into a SHA-256 hash chain — retroactive edits break the chain, and Merkle block roots can be shared with auditors for independent verification.

Hosting & residency

Single-region deployment today; Mumbai-region India hosting planned. No cross-border replication is built into the architecture.

Role-based access

Session-based auth with role + attribute permission checks enforced on every /api route — doctors see clinical data, admins see financials, patients see their own records.

Consent-first

Consent is captured as granted/denied per purpose (treatment, data share, research, telemedicine) and every capture is audit-logged. Withdrawal requests are handled via the clinic desk.

Breach response

Breach-response playbook defined; automated detection planned. Incidents are reviewed manually today through the incident module.

Your DPDP rights

How to exercise them today — self-serve where the product supports it, clinic-desk assisted where it is manual.

Access & export your data

Foresight Settings → “Download my data (JSON)” exports everything the engine stores about you. For hospital records, ask at the clinic desk.

Correct inaccurate data

Raise corrections with your doctor or the clinic desk. Fixes are made on the source record, and every change lands in the audit trail.

Withdraw consent & delete

Settings → “Delete all my runs” wipes your Foresight data instantly. Hospital consents (treatment, data share, research) are withdrawn via the clinic desk — and audit-logged.

Grievance redressal

Start at the clinic desk, or email compliance@nexuraai.in. Every request is logged and tracked to closure.

Need a compliance audit?

Our team can walk you through every regulation and how Nexura OS addresses it.

Contact compliance team

Command Palette

Search for a command to run...