Employee health data is sensitive. We protect it with strong encryption, strict access controls and India-first compliance — so trust is never a trade-off for your HR team or your people.
Every layer of StarFit — from how the app handles a login to how a lab report reaches your phone — is built assuming the data in it is sensitive by default. Employers get visibility into usage. They never get visibility into your health.
Certifications and audits are in active progress as part of our enterprise readiness roadmap — ask your account team for our current compliance status and documentation.
Health and personal data is encrypted in transit (TLS) and at rest, with strict key management.
Only authorised StarFit personnel and your care team can access identifiable health records, on a least-privilege basis.
HR admins see plan usage and roster data — never an individual employee's diagnosis, prescriptions or consult notes.
We collect only what's needed to deliver the benefit, and retain it only as long as required by law or your contract.
Every hospital, lab and pharmacy partner is verified before joining the network, and re-reviewed on an ongoing basis.
A documented incident-response process, with breach notification obligations under the DPDP Act 2023 taken seriously.
Organised the way a vendor security questionnaire is — so your procurement and InfoSec teams can find what they need without a back-and-forth.
Employees with access to sensitive data undergo background verification before joining.
Mandatory security and data-handling training at onboarding, refreshed periodically.
Every employee and contractor signs confidentiality terms covering member health data.
Internal access to production systems is reviewed on a recurring basis and revoked on role change or exit.
TLS for data moving between systems; encryption at rest for stored health and personal data.
Production systems run in isolated network segments, separated from development and staging environments.
Regular automated backups with tested restore procedures, so an infrastructure failure doesn't mean data loss.
Hosted on established cloud infrastructure providers with their own independently audited security controls.
HR admins, care providers and internal staff each see only what their role requires — enforced in the application layer, not just policy.
Access to sensitive records is logged, so any access to a member's health data can be traced.
Code changes go through review before reaching production; dependencies are monitored for known vulnerabilities.
Security issues reported through our responsible disclosure process are triaged and remediated on a risk-based timeline.
Need this in questionnaire or documentation form for your procurement process? Ask your account team — we're set up to respond to security reviews directly rather than pointing you back to this page.
If you believe you've found a vulnerability in our platform, please report it responsibly to info@starfitindia.com before disclosing it publicly. We investigate every report and will acknowledge receipt within 2 business days.