Clinical media is already being captured — on personal phones, in consumer drives, over messaging apps. Mextt doesn't ask clinicians to stop; it gives them a place to do it that actually protects them, the patient, and the institution.
We publish status, not promises. If a badge isn't earned yet, it says so.
| HIPAA-ready architecture — BAA template | Ready |
| AES-256 at rest & in transit · signed URLs | Active |
| No model training on customer data | Contractual |
| SOC 2 Type II | On roadmap |
| NABH-compatible audit trails, RBAC, retention | Ready |
| India-region data residency | Active |
| DPDP Act 2023 — consent & data-subject rights | In progress |
| ISO 27001 | In certification |
B2B contract, data-processing agreement, security terms. The institution owns its data; exit terms are explicit.
Structured note, case record, team access, quality review — covered by the hospital's updated procedural consent. We provide the model clause.
Teaching clips, portfolios, training libraries require explicit consent. The clinician marks the case; the platform enforces the restriction until consent is confirmed.
Send us your security questionnaire or DPA — we answer architecture diagrams, data-flow maps, and policy docs directly, in parallel with the pilot conversation.