BOOK A DEMO

Let's find the right plan for your team

Tell us a bit about your company — our team gets back to you within one working day.

By submitting you agree to StarFit's privacy policy.

HOW STARFIT WORKS

Up and running in three simple steps

STEP 01
Choose your plan

Pick the modules and consult options that fit your headcount, locations and budget.

STEP 02
Employees activate

Self-onboarding via app — employees and dependents are covered in minutes.

STEP 03
Access benefits

Cashless consults, diagnostics, pharmacy and wellness — across India, day one.

Book a Demo →
TRUST & SECURITY

Enterprise-grade trust, by default

Employee health data is sensitive. We protect it with strong encryption, strict access controls and India-first compliance — so trust is never a trade-off for your HR team or your people.

Abstract representation of StarFit's layered data security

Security isn't a feature we bolted on

Every layer of StarFit — from how the app handles a login to how a lab report reaches your phone — is built assuming the data in it is sensitive by default. Employers get visibility into usage. They never get visibility into your health.

DPDP Act 2023 aligned ISO 27001-aligned controls SOC 2-style audit practices 256-bit encryption in transit & at rest

Certifications and audits are in active progress as part of our enterprise readiness roadmap — ask your account team for our current compliance status and documentation.

HOW WE PROTECT YOUR DATA

Built with privacy-by-design principles

Encryption everywhere

Health and personal data is encrypted in transit (TLS) and at rest, with strict key management.

Role-based access

Only authorised StarFit personnel and your care team can access identifiable health records, on a least-privilege basis.

Employer never sees clinical detail

HR admins see plan usage and roster data — never an individual employee's diagnosis, prescriptions or consult notes.

Data minimisation

We collect only what's needed to deliver the benefit, and retain it only as long as required by law or your contract.

Vendor & partner vetting

Every hospital, lab and pharmacy partner is verified before joining the network, and re-reviewed on an ongoing basis.

Incident response

A documented incident-response process, with breach notification obligations under the DPDP Act 2023 taken seriously.

OUR SECURITY PROGRAM

What we cover when your security team reviews us

Organised the way a vendor security questionnaire is — so your procurement and InfoSec teams can find what they need without a back-and-forth.

Corporate Security
Background checks

Employees with access to sensitive data undergo background verification before joining.

Security training

Mandatory security and data-handling training at onboarding, refreshed periodically.

Confidentiality agreements

Every employee and contractor signs confidentiality terms covering member health data.

Access reviews

Internal access to production systems is reviewed on a recurring basis and revoked on role change or exit.

Infrastructure Security
Encryption in transit & at rest

TLS for data moving between systems; encryption at rest for stored health and personal data.

Network isolation

Production systems run in isolated network segments, separated from development and staging environments.

Automated backups

Regular automated backups with tested restore procedures, so an infrastructure failure doesn't mean data loss.

Vetted cloud infrastructure

Hosted on established cloud infrastructure providers with their own independently audited security controls.

Product Security
Role-based access control

HR admins, care providers and internal staff each see only what their role requires — enforced in the application layer, not just policy.

Audit logging

Access to sensitive records is logged, so any access to a member's health data can be traced.

Secure development lifecycle

Code changes go through review before reaching production; dependencies are monitored for known vulnerabilities.

Vulnerability management

Security issues reported through our responsible disclosure process are triaged and remediated on a risk-based timeline.

Need this in questionnaire or documentation form for your procurement process? Ask your account team — we're set up to respond to security reviews directly rather than pointing you back to this page.

Grievance Officer & data requests

Under the Digital Personal Data Protection Act, 2023, StarFit India Private Limited maintains a designated Grievance Officer to handle data-privacy complaints and requests from employees and their dependents. Full details are on our Grievance Redressal page.

info@starfitindia.com +91 90003 55100
Found a security issue?

If you believe you've found a vulnerability in our platform, please report it responsibly to info@starfitindia.com before disclosing it publicly. We investigate every report and will acknowledge receipt within 2 business days.