Leading child development centers and neuroscience professionals rely on NeuroHue to manage sensitive developmental data. We take this trust seriously and operate with security, privacy, and child safety as foundational principles.
Compliance
Our information security program is built on the foundation of India’s Digital Personal Data Protection (DPDP) Act, 2023.
- DPDP Act 2023: Fully compliant with India’s latest privacy laws, including verifiable parental consent and strict purpose limitation.
- HIPAA Aligned: While based in India, our controls align with global HIPAA standards for healthcare data protection.
Compliance alone is not security. We implement additional safeguards to ensure safety is enforced in practice — not just on paper.
Security in the Product
- Secure Staff Login (MFA): Mandatory OTP / email verification ensures stolen passwords cannot grant access.
- Indian Data Residency: All customer data is hosted within India (Mumbai region), adhering strictly to data localization laws.
- Parent-Controlled Data Retention: Clinics can archive or delete records upon parental request, ensuring data is retained only as long as legally required.
- Full Activity History (Audit Logs): Every view or edit of a child’s record is logged and auditable for complete accountability.
- Granular Access Control: Role-based permissions ensure staff only access information relevant to their role.
Security in the Organization
- Restricted Production Access: Only a small group of core engineers can access live systems, strictly for maintenance.
- Child Safety & Privacy Training: Mandatory onboarding and annual training for all employees.
- Automated Threat Detection: Continuous monitoring to detect and respond to suspicious activity.
- Privacy-First Culture: Zero tracking policy. We never sell, analyze, or use child data for marketing.
Reporting Security Vulnerabilities
We value responsible disclosure from security researchers and the community.
If you discover a vulnerability, please report it via our support channel. We ask that you follow these guidelines:
- Do not access or modify data that does not belong to you.
- Do not violate Indian laws (including the IT Act, 2000).
- Do not disrupt services (e.g. denial-of-service attacks).
Out of Scope
- Social engineering or phishing attempts.
- Physical security attacks on offices or data centers.
