FtunMed

Security & Compliance

Healthcare data protection built into the platform

FtunMed is designed for environments where health data requires strict identity proofing, encryption, access control, and auditability — from individual facilities to national health programs.

Security architecture

Identity

FtunHealth ID serves as the single source of truth for patient and provider identity across the platform, with strong identity-proofing at enrollment.

Encryption

TLS 1.3 for data in transit. AES-256 encryption at rest. Field-level encryption for sensitive data categories including clinical records and identifiers.

Access control

Role-based and attribute-based access control, scoped to the minimum necessary data for each user, role, and clinical context.

Zero Trust

No implicit trust between services. Every internal API call is authenticated and authorized — including communication between FtunOS microservices.

Audit

Immutable, queryable logs of every data access and change. Audit trails are available to compliance teams, facility administrators, and patients as appropriate.

Compliance

Architecture aligned with Ethiopian data protection and health information regulations, with extensibility to regional and international compliance frameworks as deployments expand.

Disaster recovery

Multi-region backup strategy with defined recovery time objectives. Offline-capable local caching supports continuity when connectivity is intermittent.

High availability

Redundant infrastructure across availability zones. The platform is designed for graceful degradation rather than full outage when individual components fail.

Monitoring

Continuous security monitoring with anomaly detection and health-data-specific incident response procedures.

Security and compliance inquiries

Hospital IT teams, regulators, and enterprise buyers can request detailed security documentation through a direct conversation with our team. A downloadable security whitepaper is not yet available.

Request security documentation