- Transport encryption on everything, with HSTS and no downgrade path.
- Encryption at rest for the database and for backups.
- Per-person accounts. No shared logins internally, for the same reason we do not allow them in the product.
- Every access to a patient record is logged, including ours.
- Dependencies are monitored for known vulnerabilities.
- A content security policy that permits no inline script beyond a fixed set of hashes.
What we do not claim
We do not hold ISO 27001 or SOC 2 today. Saying so is more useful to you than a page implying otherwise. If a certification becomes a requirement for you, tell us — it affects our roadmap.
NADI · DOCUMENT
● Status current
● Plain language yes
● Contact stated
✓ published, dated, binding
We would rather you checked. All of it is written down.
How we are paid, what we will not build, and the reasons to be suspicious.