Skip to content
Trust & security

Donor records, handled like donor records

RAKT holds identifiable donor and recipient health data. This page is the straight answer to what we do with it, where it lives, who can reach it and what happens when something goes wrong — written to be handed to whoever fills in your security questionnaire.

Access

Shared passwords are the actual threat

In a blood centre the realistic breach is not an attacker — it is one login that six people on a shift know.

Passkey sign-in

Phishing-resistant WebAuthn passkeys. Staff sign in with a device they hold, not a password that can be written on a note by the terminal.

Role-based access

Permissions granted per role and per centre, changed centrally. A phlebotomist does not get the issue screen because nobody had time to set roles up.

Least privilege by default

A new account starts with the minimum its role needs. There is no shared administrator login to fall back on.

Audit log on every record

Who changed what, when, retained and searchable. Corrections are recorded as corrections rather than overwriting the original.

Data residency

Where your data lives

Donor and recipient records are stored and backed up on infrastructure in India (Bengaluru and Mumbai). That is where the application and its backups live.

A short list of named providers still process limited data outside India in order to deliver the Service: email, SMS and WhatsApp delivery, error monitoring, and optional artificial intelligence features that a centre must enable. The current list, with purpose and location for each, is at rakt.in/subprocessors/. We would rather say so plainly than imply that nothing ever leaves the country.

Traffic is encrypted in transit and data is encrypted at rest. Backups run regularly and restoration is tested, because a backup nobody has restored from is a hypothesis rather than a backup. Each centre’s records are logically separated, and that boundary is enforced by the application.

Statutory position

What RAKT is built to satisfy

Stated precisely, because “compliant” on its own means nothing.

Drugs and Cosmetics Act registers

Every register a licensed blood centre is required to maintain is generated from live records, in the form an inspector expects.

NABH performance indicators

The indicators are derived from the day’s work rather than compiled by hand before an assessment.

eRaktKosh reporting

Integrated with the national eRaktKosh system, so submission is built from records that already exist.

ABDM and ABHA

Integrated with the Ayushman Bharat Digital Mission for ABHA-based donor identity, under the National Health Authority’s specifications.

ICCBBA / ISBT 128

Registered software vendor for ISBT 128 labeling — data structures from the bag record.

A note on what we do not claim: RAKT does not hold ISO 27001, ISO 13485 or a CDSCO device licence, and you will not find those logos on this site. ICCBBA registration is stated as vendor status for ISBT 128, not as “ICCBBA certified”. Several vendors in this market display certifications that belong to a different entity or a different product. If a certificate matters to your procurement process, ask us and we will tell you plainly whether we have it.

When something goes wrong

What we commit to

01

We tell you

If an incident affects your centre’s data you hear it from us, with what we know at the time, rather than finding out later.

02

We tell you what we do not know yet

An early notice with gaps is more useful than a complete one that arrives a fortnight late.

03

We write down what changed

Every incident produces a specific change to the product or the operation, and we will tell you what it was.

FAQ

Security questions we get asked

Where is our data hosted?

Stored and backed up on infrastructure in India. Named providers for email, messaging, error monitoring and optional AI features process limited data outside India; the list is at rakt.in/subprocessors/.

Is RAKT ISO 27001 certified?

No. We would rather say so than imply otherwise — certification claims are checkable, and in this market they are checked. What we do have is described on this page: passkey authentication, role-based access, encryption in transit and at rest, an audit log on every record, and hosting in India.

Is RAKT registered with ICCBBA?

Yes. RAKT is registered with ICCBBA as a software vendor for the ISBT 128 Standard. See the ISBT 128 feature page for what that covers in the product, and ask support@rakt.in if you need confirmation for a questionnaire.

Can one centre see another centre’s donors?

No. Records are logically separated per centre and the boundary is enforced by the application, not by which login somebody happens to use.

How do staff sign in?

With WebAuthn passkeys bound to a device, which removes the shared-password problem that is the most common real weakness in a blood centre. Roles are granted per person and per centre and can be revoked centrally the day someone leaves.

Do you keep an audit trail we can use in an inspection?

Yes. Every record carries who created or changed it and when, retained and searchable. Corrections are stored as corrections, so the original entry is still there.

Will you complete our security questionnaire?

Yes. Send it to support@rakt.in. Answers that are "no" will say no.