Skip to content
DawaSmartHMIS

Security and compliance

What is in place, what is in progress, and what is on the roadmap.

Hospital procurement and data protection officers need a straight answer to each question. This page is that answer, kept in step with the evidence pack we have submitted to the Digital Health Agency.

A nurse unlocking a tablet with a fingerprint in a hospital ward
Biometric unlock · mobile app

Compliance ledger

Every claim, with its status.

Flip through the three groups. Nothing here is marked as in place without evidence we can show you.

In place7 items
  • Registered Data Processor

    ODPC registration 446-3745-BB21

    Safravo Ltd is registered with the Office of the Data Protection Commissioner (Kenya) as a Data Processor, registration number 446-3745-BB21, valid 29 September 2026 to 29 September 2028.

    Evidence: Certificate of Registration, serial 28485

  • Independent penetration test

    Tested by ISP Kenya, 2026

    An external penetration test and vulnerability assessment of the DawaSmart platform was carried out by ISP Kenya in 2026. Findings were remediated and confirmed by a retest. Reports are available to prospective customers under NDA.

    Evidence: Penetration test and retest reports

  • Encrypted in transit

    TLS 1.2 and 1.3 only

    All traffic between browsers, the mobile app and the DawaSmart servers uses HTTPS. The public endpoints accept TLS 1.2 and TLS 1.3 and reject TLS 1.0 and 1.1. The web workspace enforces HSTS and a Content Security Policy.

    Evidence: External TLS handshake verification

  • Role and permission based access

    Facility, branch and department scoped

    Every user has an individual account. Access is granted by role and granular permission, and every record is scoped to the facility and, where relevant, the branch. A cashier never sees clinical notes; a clinician never changes prices.

    Evidence: Access Control Policy

  • Audit trail

    Who did what, when

    State-changing clinical and financial actions are recorded with the user, action, record, time and request context, and can be reviewed by authorised facility administrators.

    Evidence: Audit Trail Specification

  • Cloud firewall and server backups

    HTTPS only; restricted administration

    The production environment sits behind a cloud firewall that admits HTTPS from the internet and administrative access only from named addresses. Provider-level server backups are enabled.

    Evidence: Infrastructure configuration

  • Hosting and data location

    DigitalOcean, United States

    DawaSmart is hosted on DigitalOcean infrastructure in the SFO2 region (San Francisco, United States), under DigitalOcean's terms and data processing agreement. We state this plainly so your data protection officer can assess the transfer; the position is documented in our DPIA and privacy policy.

    Evidence: Cloud Service Provider Agreement

In progress2 items
  • Digital Health Agency certification

    Application submitted

    DawaSmart's application and supporting evidence pack have been submitted to the Digital Health Agency for certification. We will update this page when the outcome is issued.

    Evidence: Application in review

  • Off-site database backup and restore test

    Being implemented

    A nightly database backup stored outside the hosting provider, with a documented restore test, is being implemented to complement the provider-level server backups.

    Evidence: Backup and Recovery Policy

Roadmap2 items
  • SHA electronic claims

    Roadmap

    DawaSmart records payer and insurance details, pre-authorisations and claims for every visit, and the claims workflow is built with an adapter for the Social Health Authority. Live electronic submission to SHA depends on SHA's provider onboarding and conformance, and is on the roadmap rather than claimed today.

    Evidence: Interoperability roadmap

  • Kenya HIE and FHIR exchange

    Roadmap

    Exchange with the Kenya Health Information Exchange, HL7 FHIR interfaces and KHIS reporting are planned through the Digital Health Agency conformance process. They are not implemented today.

    Evidence: Interoperability roadmap

Network boundaries

Four boundaries, each with its own controls.

The same description appears in our Technical Specifications document.

  1. 1

    Internet to edge

    Facility workspaces are served through Cloudflare. Public endpoints accept TLS 1.2 and 1.3 only.

  2. 2

    Edge to application

    A reverse proxy terminates HTTPS and forwards to application processes bound to the server's loopback interface; a cloud firewall admits HTTPS from the internet and administration only from named addresses.

  3. 3

    Application

    Bearer-token authentication, role and permission guards, facility and branch scoping on every query, strict input validation, rate limiting and security headers.

  4. 4

    Data

    Database and object storage are reached only by the application with protected credentials. Selected integration secrets are encrypted in the application.

Access inside the hospital

Individual accounts. Roles and granular permissions. Scoped to facility and branch.

  • Every staff member has their own account; shared logins are not needed because the mobile app supports biometric unlock on shared devices
  • Permissions are granular: a user can be allowed to dispense but not to adjust stock, to bill but not to discount, to view reports but not to export them
  • Discounts and waivers go through an approval step
  • Exports that contain patient or sales data require a separate Export reports permission
  • Administrators can review the audit trail of who did what and when

Data ownership and exit

Your data stays yours.

The hospital is the data controller and Safravo is its processor. You can export records at any time. On exit we return your data in standard formats and confirm deletion in line with the agreed retention schedule. Our Data Processing Agreement, Privacy Policy and DPIA are available to prospective customers on request.

Documents available on request

  • · Data Processing Agreement
  • · Privacy Policy
  • · Data Protection Impact Assessment
  • · Technical Specifications
  • · System Architecture
  • · Information Security Policy
  • · Incident Response Plan
  • · Penetration test summary (under NDA)

Next step

Send this page to your IT and data protection teams, then book the technical demo.

We are happy to walk your IT lead through the architecture, the permission model and the test reports before a commercial conversation.

Or call +254 746 289 413 · Monday to Saturday, 8:00 to 18:00 EAT