ISO 27001
Annual third-party audit. Independent verification of information security management systems.
Refill Health is built on a security and compliance posture that meets the rigorous requirements of enterprise procurement, clinical governance, and Indian and international data protection law.
ISO 27001
CERTIFIED
HIPAA
ALIGNED
GDPR
ALIGNED
DPDP Act 2023
COMPLIANT
COMPLIANCE POSTURE
We don't claim what we don't have. Below is the actual commitment level for each framework — certified, aligned, or compliant.
Annual third-party audit. Independent verification of information security management systems.
Refill Health follows HIPAA Privacy and Security Rule controls applicable to health data. We are not a US Covered Entity; alignment is voluntary and operational.
EU/UK data subject rights and processor obligations are implemented in product and contract. Data Processing Agreements available for European clients.
India's Digital Personal Data Protection Act — fully implemented across consent, data fiduciary duties, and grievance redressal.
DATA ARCHITECTURE

AWS-hosted, India-resident by default for all client data. Cross-region transfer requires explicit client consent and a contractual data processing agreement.
AES-256 encryption at rest. TLS 1.3 in transit. Database-level field encryption for clinical and personally identifiable data.
Role-based access control (RBAC) across all systems. Multi-factor authentication mandatory for all internal users. Least-privilege access enforced architecturally.
Clinical data, HR analytics data, and member self-care data are stored separately. The audience boundary is enforced at the database layer, not just the application layer.
Member-controlled data retention with documented deletion windows. Right-to-erasure implemented for all jurisdictions where applicable. Anonymised analytics data retained per DPDP timelines.
OPERATIONAL DISCIPLINE
Annual third-party penetration tests. Internal continuous vulnerability scanning. Findings tracked to closure with documented severity ratings.
Documented incident response plan with defined escalation paths, breach notification commitments aligned to DPDP and GDPR, and post-incident review process.
Sub-processors are reviewed for security and compliance posture before onboarding. Material changes notified to clients per data processing agreement.
Security governance reviewed quarterly by Refill Health leadership. Annual policy review. Employee security training mandatory at onboarding and annually.
Refill Health's platform is engineered for the rigour of enterprise mental healthcare — where security, privacy, and clinical governance share the same operating standard.
A platform built to international standards: ISO 27001 certified, HIPAA-aligned, GDPR-aligned, and fully DPDP-compliant.
Enterprise-grade infrastructure: AWS-hosted, India-resident, encrypted end-to-end across all data flows.
Architectural privacy controls: Clinical, HR, and self-care data segregated at the database layer; member identifiers stripped from analytics flows.
Operationally mature: Annual third-party audits, documented incident response, quarterly governance reviews, mandatory employee training.