Securityisnotafeature.It'sthefoundation.
Every byte encrypted, every access logged, every regulation met. Built for compliance officers who accept nothing less.
NexV encrypts all patient data with AES-256 at rest and TLS 1.3 in transit, using AWS KMS-managed keys. All AI processing occurs within the practice's own AWS environment with no third-party data processors. Full audit trails via CloudTrail log every access and modification.
Certifications
The standards your board expects.
HIPAA
BAA AvailableHIPAA-aligned architecture with a signed Business Associate Agreement for every US practice before any PHI transfer. All protected health information handled under strict regulatory controls.
Download BAA →SOC 2 Type II
On Our RoadmapApplication-layer SOC 2 Type II is planned as NexV scales. NexV runs entirely on AWS infrastructure, which maintains its own SOC 2 Type II attestation.
Australian Privacy Principles
CompliantBuilt to comply with the Australian Privacy Act 1988 and all 13 APPs. Cross-border data handling follows OAIC guidance.
End-to-End Encryption
AES-256 / TLS 1.3AES-256 encryption at rest, TLS 1.3 in transit. Zero plain-text storage of PHI at any layer of the stack.
Data Residency
AWS US-HostedAll data is hosted on AWS US infrastructure with region-locked storage. Additional regions, including Australia, are planned as we scale.
Security Scanning
Every ReleaseAutomated CodeQL analysis and dependency audits run on every release. Independent penetration testing is planned as part of our SOC 2 roadmap.
Architecture
How your data is protected.
Access Controls
Enterprise-grade access at every layer.
Fine-grained permissions, immutable audit trails, and enforced authentication policies. Every action attributable to a named user.
Role-Based Access
Granular permissions matrix with 6 roles across 19 operations. Every user sees only what their role requires.
Audit Logging
Every PHI access logged with timestamp, user, action, and IP. Immutable audit trail with long-term retention.
Session Management
Configurable session timeouts with forced re-authentication. Idle sessions terminated automatically per your policy.
Multi-Factor Authentication
TOTP and SMS-based MFA available for all staff accounts. Hardware key support available for enterprise deployments.
Deep Dive
Compliance, in detail.
HIPAA BAA
Signed Business Associate Agreement included with every US subscription. Covers all PHI processed, stored, and transmitted through the platform. Breach notification within 60 days of discovery.
View BAA →SOC 2 Roadmap
Application-layer SOC 2 Type II is on our compliance roadmap. NexV inherits physical and infrastructure controls from AWS, which maintains its own SOC 2 Type II attestation, and every release passes automated security scanning.
APP Compliance Scope
All 13 Australian Privacy Principles addressed, including cross-border disclosure (APP 8) and data quality (APP 10).
Data Residency Options
Production is hosted on AWS us-east-1 with region-locked storage and no cross-region replication. Additional deployment regions, including AWS ap-southeast-2 for Australia, are planned.
Encryption Specifications
AES-256 encryption for data at rest via AWS KMS envelope encryption. TLS 1.3 enforced for all data in transit.
Incident Response
Security incidents receive priority response, with root cause analysis shared with affected practices. HIPAA breach notification within 60 days of discovery.
Need our security documentation?
We will send you our security architecture overview, HIPAA documentation, and Business Associate Agreement. Response within one business day.