Data governance
Define what data the system may use, where it is processed and how long it is retained.
Trust centre
Security, privacy and clinical safety are reviewed together because every production agent touches a combination of people, data, decisions and actions.
Core controls
The exact control set depends on the deployment, integrations and data involved. These are the foundations we expect every system to address.

Define what data the system may use, where it is processed and how long it is retained.
Restrict access by role and maintain evidence of sensitive data and system access.
Protect information in transit and at rest across the services involved in each deployment.
Separate provider environments, credentials, policies and operational data.
Review interactions, system decisions, tool actions, policy outcomes and human overrides.
Maintain clear ownership, escalation and communication for security and safety events.
Research signal
Plausible ≠ safeWHO warns that health-related LLM responses may appear authoritative while containing serious errors, and calls for expert supervision and rigorous evaluation.
WHO · Safe and ethical AI for healthIn practice
Iksha reviews what the agent understood, the policy it applied, the action it took and when a person overrode it.
Review framework
We keep claims precise. Current certifications, deployment-specific responsibilities and available evidence are confirmed during the review rather than implied by a badge.
| Area | How we address it | Review evidence |
|---|---|---|
| Healthcare privacy | Patient-data access, consent, processing, retention and disclosure are configured for the deployment context. | Data-flow documentation and deployment controls |
| Security assurance | Infrastructure, access, change and incident controls are reviewed as part of enterprise deployment. | Security brief and supporting evidence |
| India DPDP | Consent, purpose limitation, data rights and notices are reflected in product and operational design. | Data processing and consent documentation |
| Clinical safety | Permitted actions, human authority and escalation are defined for the use case before production. | Safety specification and evaluation evidence |
Shared responsibility
We define responsibilities across Iksha, the healthcare provider and technology partners before launch—covering data, integrations, access, monitoring, incidents and clinical escalation.
Agree what the agent may access, communicate and do.
Document controls, evaluations, operational ownership and known limitations.
Review performance, incidents and changes throughout the deployment.
We will walk through the architecture, responsibilities and evidence relevant to your deployment.