Donor records, handled like donor records
RAKT holds identifiable donor and recipient health data. This page is the straight answer to what we do with it, where it lives, who can reach it and what happens when something goes wrong — written to be handed to whoever fills in your security questionnaire.
Shared passwords are the actual threat
In a blood centre the realistic breach is not an attacker — it is one login that six people on a shift know.
Passkey sign-in
Phishing-resistant WebAuthn passkeys. Staff sign in with a device they hold, not a password that can be written on a note by the terminal.
Role-based access
Permissions granted per role and per centre, changed centrally. A phlebotomist does not get the issue screen because nobody had time to set roles up.
Least privilege by default
A new account starts with the minimum its role needs. There is no shared administrator login to fall back on.
Audit log on every record
Who changed what, when, retained and searchable. Corrections are recorded as corrections rather than overwriting the original.
Where your data lives
Donor and recipient records are stored and backed up on infrastructure in India (Bengaluru and Mumbai). That is where the application and its backups live.
A short list of named providers still process limited data outside India in order to deliver the Service: email, SMS and WhatsApp delivery, error monitoring, and optional artificial intelligence features that a centre must enable. The current list, with purpose and location for each, is at rakt.in/subprocessors/. We would rather say so plainly than imply that nothing ever leaves the country.
Traffic is encrypted in transit and data is encrypted at rest. Backups run regularly and restoration is tested, because a backup nobody has restored from is a hypothesis rather than a backup. Each centre’s records are logically separated, and that boundary is enforced by the application.
What RAKT is built to satisfy
Stated precisely, because “compliant” on its own means nothing.
Drugs and Cosmetics Act registers
Every register a licensed blood centre is required to maintain is generated from live records, in the form an inspector expects.
NABH performance indicators
The indicators are derived from the day’s work rather than compiled by hand before an assessment.
eRaktKosh reporting
Integrated with the national eRaktKosh system, so submission is built from records that already exist.
ABDM and ABHA
Integrated with the Ayushman Bharat Digital Mission for ABHA-based donor identity, under the National Health Authority’s specifications.
ICCBBA / ISBT 128
Registered software vendor for ISBT 128 labeling — data structures from the bag record.
A note on what we do not claim: RAKT does not hold ISO 27001, ISO 13485 or a CDSCO device licence, and you will not find those logos on this site. ICCBBA registration is stated as vendor status for ISBT 128, not as “ICCBBA certified”. Several vendors in this market display certifications that belong to a different entity or a different product. If a certificate matters to your procurement process, ask us and we will tell you plainly whether we have it.
What we commit to
We tell you
If an incident affects your centre’s data you hear it from us, with what we know at the time, rather than finding out later.
We tell you what we do not know yet
An early notice with gaps is more useful than a complete one that arrives a fortnight late.
We write down what changed
Every incident produces a specific change to the product or the operation, and we will tell you what it was.
Security questions we get asked
Where is our data hosted?
Stored and backed up on infrastructure in India. Named providers for email, messaging, error monitoring and optional AI features process limited data outside India; the list is at rakt.in/subprocessors/.
Is RAKT ISO 27001 certified?
No. We would rather say so than imply otherwise — certification claims are checkable, and in this market they are checked. What we do have is described on this page: passkey authentication, role-based access, encryption in transit and at rest, an audit log on every record, and hosting in India.
Is RAKT registered with ICCBBA?
Yes. RAKT is registered with ICCBBA as a software vendor for the ISBT 128 Standard. See the ISBT 128 feature page for what that covers in the product, and ask support@rakt.in if you need confirmation for a questionnaire.
Can one centre see another centre’s donors?
No. Records are logically separated per centre and the boundary is enforced by the application, not by which login somebody happens to use.
How do staff sign in?
With WebAuthn passkeys bound to a device, which removes the shared-password problem that is the most common real weakness in a blood centre. Roles are granted per person and per centre and can be revoked centrally the day someone leaves.
Do you keep an audit trail we can use in an inspection?
Yes. Every record carries who created or changed it and when, retained and searchable. Corrections are stored as corrections, so the original entry is still there.
Will you complete our security questionnaire?
Yes. Send it to support@rakt.in. Answers that are "no" will say no.