Security & Compliance

Securityisnotafeature.It'sthefoundation.

Every byte encrypted, every access logged, every regulation met. Built for compliance officers who accept nothing less.

NexV encrypts all patient data with AES-256 at rest and TLS 1.3 in transit, using AWS KMS-managed keys. All AI processing occurs within the practice's own AWS environment with no third-party data processors. Full audit trails via CloudTrail log every access and modification.

The standards your board expects.

HIPAA

BAA Available

HIPAA-aligned architecture with a signed Business Associate Agreement for every US practice before any PHI transfer. All protected health information handled under strict regulatory controls.

Download BAA

SOC 2 Type II

On Our Roadmap

Application-layer SOC 2 Type II is planned as NexV scales. NexV runs entirely on AWS infrastructure, which maintains its own SOC 2 Type II attestation.

Australian Privacy Principles

Compliant

Built to comply with the Australian Privacy Act 1988 and all 13 APPs. Cross-border data handling follows OAIC guidance.

End-to-End Encryption

AES-256 / TLS 1.3

AES-256 encryption at rest, TLS 1.3 in transit. Zero plain-text storage of PHI at any layer of the stack.

Data Residency

AWS US-Hosted

All data is hosted on AWS US infrastructure with region-locked storage. Additional regions, including Australia, are planned as we scale.

Security Scanning

Every Release

Automated CodeQL analysis and dependency audits run on every release. Independent penetration testing is planned as part of our SOC 2 roadmap.

How your data is protected.

Your Practice
TLS 1.3
AWS Infrastructure
AppSync API
DynamoDB (AES-256)
S3 Documents (SSE)
CloudTrail Audit
Envelope Encryption
AWS KMS

Enterprise-grade access at every layer.

Fine-grained permissions, immutable audit trails, and enforced authentication policies. Every action attributable to a named user.

Role-Based Access

Granular permissions matrix with 6 roles across 19 operations. Every user sees only what their role requires.

Audit Logging

Every PHI access logged with timestamp, user, action, and IP. Immutable audit trail with long-term retention.

Session Management

Configurable session timeouts with forced re-authentication. Idle sessions terminated automatically per your policy.

Multi-Factor Authentication

TOTP and SMS-based MFA available for all staff accounts. Hardware key support available for enterprise deployments.

Compliance, in detail.

HIPAA BAA

Signed Business Associate Agreement included with every US subscription. Covers all PHI processed, stored, and transmitted through the platform. Breach notification within 60 days of discovery.

View BAA

SOC 2 Roadmap

Application-layer SOC 2 Type II is on our compliance roadmap. NexV inherits physical and infrastructure controls from AWS, which maintains its own SOC 2 Type II attestation, and every release passes automated security scanning.

APP Compliance Scope

All 13 Australian Privacy Principles addressed, including cross-border disclosure (APP 8) and data quality (APP 10).

Data Residency Options

Production is hosted on AWS us-east-1 with region-locked storage and no cross-region replication. Additional deployment regions, including AWS ap-southeast-2 for Australia, are planned.

Encryption Specifications

AES-256 encryption for data at rest via AWS KMS envelope encryption. TLS 1.3 enforced for all data in transit.

Incident Response

Security incidents receive priority response, with root cause analysis shared with affected practices. HIPAA breach notification within 60 days of discovery.

Need our security documentation?

We will send you our security architecture overview, HIPAA documentation, and Business Associate Agreement. Response within one business day.