Information security management
01
ISO 27001 Certified
Information security management
ISO/IEC 27001 is the internationally recognised standard for Information Security Management Systems (ISMS). It sets out how organisations identify risks, protect information assets, and continuously improve security controls.
Our certification means MediQry follows a documented framework covering access control, encryption, incident response, vendor management, and staff security training — so your health and account data are handled with the same discipline expected of enterprise systems.
Independent auditors periodically review our controls against the ISO 27001 requirements. That external check gives patients and doctors confidence that security is not just a claim — it is measured and maintained.
Trust services for cloud platforms
02
SOC 2 Certified
Trust services for cloud platforms
SOC 2 (System and Organization Controls 2) is a rigorous audit framework developed by the AICPA. It evaluates how a service organisation protects customer data across security, availability, processing integrity, confidentiality, and privacy.
For MediQry, SOC 2 focuses on the systems that power bookings, payments, profiles, and health records. Auditors examine whether our policies and technical controls actually operate as designed over time — not only on paper.
Achieving SOC 2 demonstrates that we meet industry benchmarks for cloud healthcare platforms: controlled access, monitoring, change management, and clear accountability when something needs investigation.
03
256-bit Encryption
Bank-grade protection in transit & at rest
256-bit encryption (AES-256) is the same class of cryptography used by banks and government systems. It makes intercepted data computationally infeasible to read without the correct keys.
On MediQry, sensitive traffic is protected with TLS using strong cipher suites while data moves between your device and our servers. Stored credentials and selected sensitive fields are protected with industry-standard hashing and encryption practices.
Payments are processed through Razorpay — we do not store full card or UPI credentials on MediQry servers. Encryption, key management, and least-privilege access work together so only authorised systems can unlock what they need.
How we put this into practice
- Role-based access so only authorised staff and systems can reach sensitive data
- Encrypted connections (HTTPS/TLS) for all MediQry web traffic
- Secure payment processing via trusted partners — no full card storage on our servers
- Ongoing monitoring, reviews, and security-aware product development
Questions about security?
Reach our team at security@mediqry.com or visit Contact us.