Accounts
Passwords are stored only as secure hashes. Provider and staff accounts confirm sign-in with a one-time code, and sign-in attempts are rate limited.
Access to records
Each pharmacy, doctor and lab sees only the requests sent to it. Lab reports open through links that expire, and provider bank and licence details are never shown publicly.
Every action by Dozio staff that changes a record is logged with who did it, when and why.
In transit
The website and apps talk to Dozio only over encrypted connections.
Reporting a security problem
If you find a vulnerability, email care@dozio.in with "Security" in the subject and enough detail to reproduce it. Please do not access other people's data or disrupt the service while testing.
These policies are written in plain English. If anything here is unclear, ask support.