Donor records, handled like donor records
RAKT holds identifiable donor and recipient health data. This page is the straight answer to what we do with it, where it lives, who can reach it and what happens when something goes wrong — written to be handed to whoever fills in your security questionnaire.
Shared passwords are the actual threat
In a blood centre the realistic breach is not an attacker — it is one login that six people on a shift know.
Passkey sign-in
Phishing-resistant WebAuthn passkeys. Staff sign in with a device they hold, not a password that can be written on a note by the terminal.
Role-based access
Permissions granted per role and per centre, changed centrally. A phlebotomist does not get the issue screen because nobody had time to set roles up.
Least privilege by default
A new account starts with the minimum its role needs. There is no shared administrator login to fall back on.
Audit log on every record
Who changed what, when, retained and searchable. Corrections are recorded as corrections rather than overwriting the original.
Where your data lives
In India. RAKT is hosted on infrastructure in Indian regions, and donor and recipient records do not leave the country in the course of normal operation. For a blood centre this is not a preference — it is the answer that has to be available when the question is asked.
Traffic is encrypted in transit and data is encrypted at rest. Backups run regularly and restoration is tested, because a backup nobody has restored from is a hypothesis rather than a backup.
Each centre’s records are logically separated. Staff at one centre cannot reach another centre’s donors, and that boundary is enforced by the application rather than by a convention about who logs in where.
What RAKT is built to satisfy
Stated precisely, because “compliant” on its own means nothing.
Drugs and Cosmetics Act registers
Every register a licensed blood centre is required to maintain is generated from live records, in the form an inspector expects.
NABH performance indicators
The indicators are derived from the day’s work rather than compiled by hand before an assessment.
eRaktKosh reporting
Integrated with the national eRaktKosh system, so submission is built from records that already exist.
ABDM and ABHA
Integrated with the Ayushman Bharat Digital Mission for ABHA-based donor identity, under the National Health Authority’s specifications.
A note on what we do not claim: RAKT does not hold ISO 27001, ISO 13485 or a CDSCO device licence, and you will not find those logos on this site. Several vendors in this market display certifications that belong to a different entity or a different product. If a certificate matters to your procurement process, ask us and we will tell you plainly whether we have it.
What we commit to
We tell you
If an incident affects your centre’s data you hear it from us, with what we know at the time, rather than finding out later.
We tell you what we do not know yet
An early notice with gaps is more useful than a complete one that arrives a fortnight late.
We write down what changed
Every incident produces a specific change to the product or the operation, and we will tell you what it was.
Security questions we get asked
Where is our data hosted?
On infrastructure in India. Donor and recipient records do not leave the country in normal operation.
Is RAKT ISO 27001 certified?
No. We would rather say so than imply otherwise — certification claims are checkable, and in this market they are checked. What we do have is described on this page: passkey authentication, role-based access, encryption in transit and at rest, an audit log on every record, and hosting in India.
Can one centre see another centre’s donors?
No. Records are logically separated per centre and the boundary is enforced by the application, not by which login somebody happens to use.
How do staff sign in?
With WebAuthn passkeys bound to a device, which removes the shared-password problem that is the most common real weakness in a blood centre. Roles are granted per person and per centre and can be revoked centrally the day someone leaves.
Do you keep an audit trail we can use in an inspection?
Yes. Every record carries who created or changed it and when, retained and searchable. Corrections are stored as corrections, so the original entry is still there.
Will you complete our security questionnaire?
Yes. Send it to support@rakt.in. Answers that are "no" will say no.