Security & Compliance
Healthcare data protection built into the platform
FtunMed is designed for environments where health data requires strict identity proofing, encryption, access control, and auditability — from individual facilities to national health programs.
Security architecture
Identity
FtunHealth ID serves as the single source of truth for patient and provider identity across the platform, with strong identity-proofing at enrollment.
Encryption
TLS 1.3 for data in transit. AES-256 encryption at rest. Field-level encryption for sensitive data categories including clinical records and identifiers.
Access control
Role-based and attribute-based access control, scoped to the minimum necessary data for each user, role, and clinical context.
Zero Trust
No implicit trust between services. Every internal API call is authenticated and authorized — including communication between FtunOS microservices.
Audit
Immutable, queryable logs of every data access and change. Audit trails are available to compliance teams, facility administrators, and patients as appropriate.
Compliance
Architecture aligned with Ethiopian data protection and health information regulations, with extensibility to regional and international compliance frameworks as deployments expand.
Disaster recovery
Multi-region backup strategy with defined recovery time objectives. Offline-capable local caching supports continuity when connectivity is intermittent.
High availability
Redundant infrastructure across availability zones. The platform is designed for graceful degradation rather than full outage when individual components fail.
Monitoring
Continuous security monitoring with anomaly detection and health-data-specific incident response procedures.
Security and compliance inquiries
Hospital IT teams, regulators, and enterprise buyers can request detailed security documentation through a direct conversation with our team. A downloadable security whitepaper is not yet available.
Request security documentation