Cynaps Logo
FeaturesResearchBlogAbout Us
Legal · Security

Security & Compliance

Last updated: July 8, 2026

Cynaps is built for India's Digital Personal Data Protection Act, 2023. This page describes the safeguards we operate today. It is to be read together with our Privacy Policy and Terms of Service.

1. Encryption & account security

  • Data encrypted at rest (AES-256) and in transit (TLS 1.2 or higher).
  • Passwords stored as salted bcrypt hashes; OTP-verified sign-up, contact changes and account deletion.
  • Short-lived httpOnly session cookies, device-trust controls, CSRF protection and automatic clinical session timeouts.
  • Payment card data is never stored by Cynaps — payments are tokenised and processed by Razorpay.

2. Access control & consent

  • Role-based access: nurses, receptionists and pharmacists see only the surfaces their role requires.
  • Clinician verification workflow gates clinical features; pharmacists undergo licence review.
  • Connector access (Gmail, Google Drive, WhatsApp) is enforced per-connector at runtime — no consent, no data flow. Google scopes are minimal (e.g. only files you pick from Drive).
  • Teleconsultation video is relayed in real time and not recorded.
  • Identifiers in medical imaging (DICOM) are scrubbed before any AI interpretation.

3. Where data is processed

Primary application data is stored in India. For AI inference we use enterprise APIs from Google (Gemini), Anthropic (Claude) and Groq (including audio transcription); video consultations use LiveKit; WhatsApp delivery uses Meta's WhatsApp Business API; payments use Razorpay. Some of this processing may occur on servers outside India, permitted under Section 16 of the DPDP Act and governed by data-processing agreements. Prompts sent for inference are not retained by the providers for model training, and we never use your content to train or fine-tune foundational models.

4. Incident response

  • Reportable cyber-security incidents are notified to CERT-In within 6 hours of noticing, per CERT-In directions (2022).
  • Personal-data breaches are notified to the Data Protection Board of India and affected users in accordance with the DPDP Act — detailed intimation within 72 hours of becoming aware.
  • Security records and audit logs support forensic review.

5. Your data rights

The in-app Privacy Centre lets you manage consent preferences and connector permissions, export your data, and file correction or erasure requests under the DPDP Act. Account deletion is OTP-verified with a 30-day recovery window. Details in the Privacy Policy.

6. Reporting a vulnerability

If you believe you have found a security issue, email grievance@cynaps.co with details. Please do not test against production patient data. This page is issued by NBALL Technologies India Private Limited (CIN: U62099TS2025PTC196111).

Cynaps Logo

Clinical Workflow Elevated.

© 2026 Cynaps Intelligence.
High Fidelity Clinical Data.
A product of NBALL Technologies India Private Limited.

Products

  • Features
  • Pharmacy
  • Labs
  • Pricing
  • Use Cases
  • Documentation

Company

  • About Us
  • Careers
  • Research
  • Blog

Help and security

  • Support center
  • Security & Compliance

Terms and policies

  • Privacy Policy
  • Terms of service
  • Refund Policy
  • AI Usage Policy
  • Cookie Policy
Medical Disclaimer

Cynaps Intelligence is engineered for licensed healthcare professionals. It serves as a clinical decision support tool and does not provide diagnostic or therapeutic advice directly to patients. Always triangulate clinical decisions with institutional protocols and verify dosing with current formulary data.