Skip to content
Trust & security

Donor records, handled like donor records

RAKT holds identifiable donor and recipient health data. This page is the straight answer to what we do with it, where it lives, who can reach it and what happens when something goes wrong — written to be handed to whoever fills in your security questionnaire.

Access

Shared passwords are the actual threat

In a blood centre the realistic breach is not an attacker — it is one login that six people on a shift know.

Passkey sign-in

Phishing-resistant WebAuthn passkeys. Staff sign in with a device they hold, not a password that can be written on a note by the terminal.

Role-based access

Permissions granted per role and per centre, changed centrally. A phlebotomist does not get the issue screen because nobody had time to set roles up.

Least privilege by default

A new account starts with the minimum its role needs. There is no shared administrator login to fall back on.

Audit log on every record

Who changed what, when, retained and searchable. Corrections are recorded as corrections rather than overwriting the original.

Data residency

Where your data lives

In India. RAKT is hosted on infrastructure in Indian regions, and donor and recipient records do not leave the country in the course of normal operation. For a blood centre this is not a preference — it is the answer that has to be available when the question is asked.

Traffic is encrypted in transit and data is encrypted at rest. Backups run regularly and restoration is tested, because a backup nobody has restored from is a hypothesis rather than a backup.

Each centre’s records are logically separated. Staff at one centre cannot reach another centre’s donors, and that boundary is enforced by the application rather than by a convention about who logs in where.

Statutory position

What RAKT is built to satisfy

Stated precisely, because “compliant” on its own means nothing.

Drugs and Cosmetics Act registers

Every register a licensed blood centre is required to maintain is generated from live records, in the form an inspector expects.

NABH performance indicators

The indicators are derived from the day’s work rather than compiled by hand before an assessment.

eRaktKosh reporting

Integrated with the national eRaktKosh system, so submission is built from records that already exist.

ABDM and ABHA

Integrated with the Ayushman Bharat Digital Mission for ABHA-based donor identity, under the National Health Authority’s specifications.

A note on what we do not claim: RAKT does not hold ISO 27001, ISO 13485 or a CDSCO device licence, and you will not find those logos on this site. Several vendors in this market display certifications that belong to a different entity or a different product. If a certificate matters to your procurement process, ask us and we will tell you plainly whether we have it.

When something goes wrong

What we commit to

01

We tell you

If an incident affects your centre’s data you hear it from us, with what we know at the time, rather than finding out later.

02

We tell you what we do not know yet

An early notice with gaps is more useful than a complete one that arrives a fortnight late.

03

We write down what changed

Every incident produces a specific change to the product or the operation, and we will tell you what it was.

FAQ

Security questions we get asked

Where is our data hosted?

On infrastructure in India. Donor and recipient records do not leave the country in normal operation.

Is RAKT ISO 27001 certified?

No. We would rather say so than imply otherwise — certification claims are checkable, and in this market they are checked. What we do have is described on this page: passkey authentication, role-based access, encryption in transit and at rest, an audit log on every record, and hosting in India.

Can one centre see another centre’s donors?

No. Records are logically separated per centre and the boundary is enforced by the application, not by which login somebody happens to use.

How do staff sign in?

With WebAuthn passkeys bound to a device, which removes the shared-password problem that is the most common real weakness in a blood centre. Roles are granted per person and per centre and can be revoked centrally the day someone leaves.

Do you keep an audit trail we can use in an inspection?

Yes. Every record carries who created or changed it and when, retained and searchable. Corrections are stored as corrections, so the original entry is still there.

Will you complete our security questionnaire?

Yes. Send it to support@rakt.in. Answers that are "no" will say no.