Compliance & Trust

One standards core.
Compliance modules
per jurisdiction.

Healthcare data is among the most sensitive data a person owns, and every country governs it differently. Rather than build a platform for one regulator and retrofit the rest, Zeeva separates a universal clinical core from a swappable regulatory shell. What follows is how that works, and which frameworks it maps to.

01 — Standards core

The layer that never changes.

Underneath every jurisdiction sits the same clinical and security core. These are open, internationally governed standards — not our inventions — which is precisely why they travel across borders.

FHIR
HL7 FHIR R4 / R5
HL7 International · global

The structural backbone of the entire platform. Every clinical object in Zeeva — patient, encounter, observation, condition, medication, immunisation, claim — is a FHIR resource. National implementation guides are applied as profiles on top of that core, never as forks of it.

Native · not an export format
SNOMED
LOINC
Clinical terminology
SNOMED International · Regenstrief

SNOMED CT for clinical findings, procedures and problems; LOINC for laboratory and diagnostic observations. Coded meaning rather than free text is what allows a record written in one country to be understood in another — and what makes safety checking possible at all.

Coded at the point of capture
ICD-11
DICOM
Classification & imaging
World Health Organization · NEMA

ICD-11 for diagnosis classification, morbidity and mortality reporting — the WHO standard now being adopted by member states. DICOM for medical imaging, so studies and reports move between modality, radiologist and clinician without proprietary translation.

Aligned to WHO classification
ISO
SOC 2
Security & assurance
ISO/IEC · AICPA

ISO/IEC 27001 as the information-security management baseline, with SOC 2 Type II attestation covering security, availability and confidentiality. These are the two artefacts enterprise procurement asks for first, in every market, and they are jurisdiction-independent.

ISO 27001 baseline · SOC 2 in progress

02 — Regulatory modules

The layer that changes per market.

Each jurisdiction brings its own privacy law, identity scheme, clinician registry, accreditation regime and claim format. Zeeva treats these as configuration — a module loaded per deployment — rather than as a reason to build a different product.

US
United States
HHS · ONC · CMS

HIPAA Privacy and Security Rules with Business Associate Agreements; HITECH breach notification; ONC certification criteria and information-blocking rules; US Core FHIR profiles; TEFCA-aligned exchange via Qualified Health Information Networks; NPI and state-board licence verification.

Module scoped
EU
European Union & UK
EC · EDPB · MHRA

GDPR lawful basis, data-subject rights and DPIA obligations; the European Health Data Space framework for primary and secondary use; HL7 Europe base profiles; national extensions for member states; UK GDPR and NHS interoperability standards where England, Scotland, Wales or Northern Ireland apply.

Module scoped
IN
India
NHA · MeitY · NMC

Ayushman Bharat Digital Mission — health identity, facility and professional registries, and the national consent manager; the Digital Personal Data Protection Act 2023; NRCES FHIR implementation guides; National Medical Commission licence verification; NABH and NABL accreditation status.

Module scoped
+
Additional jurisdictions
On deployment

Gulf states, Southeast Asia, Latin America and sub-Saharan Africa each have maturing national frameworks — several with published FHIR guides and enforced adoption deadlines. New modules are built against the local guide and the governing privacy statute, and certified before any patient data is processed.

Built per market, before launch
On certification status

Listing a framework here means Zeeva is architected against it and the module is scoped — not that certification is complete in every market. Zeeva is pre-launch. Current certification status per jurisdiction is provided in writing to partners during procurement review, and we will not process patient data in a market before the applicable module is certified.


03 — Data Residency

The patient's data stays in the patient's country.

Residency is not a policy we promise; it is a deployment topology. Each jurisdiction runs its own isolated data domain, with identifiable health data confined to it. Two regions inside that domain for resilience. No shadow copies elsewhere, and no cross-border movement of identifiable records between domains.

Architecture

One topology, repeated per jurisdiction.

  • Primary region — production workloads, real-time processing and the primary database cluster, inside the jurisdiction's own borders.
  • Replication region — synchronous replication, disaster recovery and automated failover, in a second region inside the same jurisdiction.
  • Daily encrypted backups retained for 35 days and archival retention set to whichever period local health-records law requires.
  • No cross-border egress of identifiable patient data between jurisdictional domains, and no third-party processor that would move it out.
  • Cryptographic isolation between data fiduciaries — multi-tenant, zero-knowledge separation.

Mapped to the data-localisation and transfer provisions of whichever statute governs the deployment — GDPR Chapter V in Europe, the DPDP Act in India, state and federal rules in the United States. Specific data-centre locations are disclosed under NDA to enterprise partners during procurement review.

Region A PRIMARY Region B REPLICA ONE JURISDICTION
04 — Security Posture

Defense in depth.

Layered security controls covering identity, network, application, data-at-rest, data-in-transit, and operational practices. Audited annually and continuously monitored.

🔐
Encryption — at rest & in transit
AES-256 for data at rest. TLS 1.3 for transit. Per-tenant key isolation with rotation. PHI fields field-level encrypted with envelope keys managed in HSM.
FIPS 140-2 Level 3 HSM
🆔
Identity & access
MFA mandatory for clinical staff. Role-based access with attribute-based overlays. All access logged, retained, and reviewable by the data principal under DPDP rights.
FIDO2 · WebAuthn
🛡️
Application security
OWASP ASVS Level 2 baseline. Quarterly third-party penetration testing. Bug bounty programme open to security researchers. Continuous SAST and DAST in the delivery pipeline.
Independent third-party audit
📊
Audit & logging
Every data access, modification and consent change is written to an immutable trail, retained per local health-records law. Patients can see who accessed their record, when, and under which consent.
Tamper-evident logs
⚠️
Incident response
24×7 SOC monitoring and documented incident-response runbooks. Breach notification to the applicable supervisory authority within the statutory window — 72 hours under GDPR, 60 days under HIPAA, and the tighter national CERT deadlines where they apply.
Per-jurisdiction notification clocks
🏗️
Operational controls
ISO/IEC 27001 baseline. SOC 2 Type II in progress. Background-verified personnel. Privileged access requires four-eyes approval and time-bound issuance.
ISO 27001 · SOC 2 Type II

05 — Designated Officers

A name. A face. A response within hours.

Most privacy regimes require a named, reachable accountable officer — a Data Protection Officer under GDPR and the DPDP Act, a privacy official under HIPAA, a grievance officer under Indian intermediary rules. We publish ours transparently rather than behind a ticketing form.

Platform grievance channel

Grievance Officer

For complaints about platform conduct, access, or a partner organisation on the network. Acknowledged within 24 hours and resolved within 15 days, the tightest standard among the regimes we operate under.

EMAIL   grievance@ecolozical.com
HOURS   Mon–Fri · 09:00 — 18:00 IST
SLA     Acknowledge 24h · Resolve 15d
GDPR Art. 37 · DPDP §10 · HIPAA

Data Protection Officer

For data-subject and data-principal rights — access, correction, erasure, portability, consent withdrawal — under GDPR, the DPDP Act, HIPAA and equivalent regimes. Independent reporting line to the board.

EMAIL   dpo@ecolozical.com
HOURS   Mon–Fri · 09:00 — 18:00 IST
SLA     Acknowledge 48h · Resolve 30d
06 — Policies

The full text.

📄
Policy versions

All policies are versioned. Material changes are notified to registered users by email and dashboard banner at least 30 days before they take effect.

Trust is not a slogan we put on a marketing page. It is a property of the architecture.

Need a security review or compliance pack?

For enterprise procurement, we maintain a vendor security questionnaire library, evidence packs, audit reports, and a dedicated compliance contact. Reach out and we'll send the right document.