Security & Compliance

Trust is the product.

Health data is the most sensitive data you own. Nevika is engineered from the ground up to protect it — with modern encryption, strict access controls, and clinical governance aligned to HIPAA and India's DPDP Act.

End-to-end encryptionHIPAA-alignedDPDP Act 2023ISO 27001 (in progress)SOC 2 (in progress)

Encryption

Every byte of your data is encrypted, in motion and at rest.

In transit

TLS 1.3 for every request between your device, our edge, and backend services. HSTS enforced. Certificate pinning on native mobile clients.

At rest

AES-256 encryption on all databases, object storage, and backups. Keys are managed with a dedicated KMS and rotated on a fixed schedule.

Field-level

Highly sensitive fields — identifiers, lab values, clinical notes — receive an additional envelope-encryption layer, isolated from application logs.

Access & governance

Least-privilege access

Role-based access control with row-level security in the database. Production access is time-bound, reviewed, and fully audit-logged.

Authentication

Multi-factor authentication for all clinician and staff accounts. Passwords hashed with modern KDFs. Sessions rotated on privilege change.

Audit trail

Every read and write to identifiable health data is logged with actor, purpose, and timestamp. Logs are tamper-evident and retained per regulation.

Secure development

Peer code review, automated dependency scanning, and secret scanning on every change. Regular third-party penetration testing.

Data handling

Your data is used to serve you — not to train third-party foundation models.

Purpose limitation

We collect only what is needed to provide care coordination, triage, and record-keeping. No sale of personal or health data, ever.

Model boundaries

Prompts and clinical content sent to AI providers are stripped of direct identifiers where possible, and are excluded from provider training by contract.

Retention & deletion

You can export or delete your data at any time. Backups roll off on a defined schedule. Legal-hold data is isolated and minimized.

Data residency

Indian user data is stored in Indian regions where feasible. Cross-border transfers use standard contractual clauses and equivalent safeguards.

Subprocessors

We use a small set of vetted subprocessors for hosting, email, analytics, and AI inference. A current list is available on request.

Breach response

Documented incident-response playbook with defined severity levels, on-call rotation, and regulator / user notification windows aligned to HIPAA and DPDP.

Compliance

HIPAA-aligned

Nevika's controls are designed against the HIPAA Security Rule — administrative, physical, and technical safeguards for protected health information. BAAs are available for eligible clinical partners in the US.

DPDP Act 2023 (India)

We operate as a Data Fiduciary under India's Digital Personal Data Protection Act — with consent-first collection, purpose limitation, grievance handling, and rights of access, correction, and erasure.

GDPR-ready

For EU users, we honor data-subject rights and use lawful bases consistent with the GDPR, including for cross-border transfers.

Certifications

ISO 27001 and SOC 2 Type II readiness programs are underway. Progress reports are shared with enterprise customers under NDA.

Your rights

  • Access a copy of your health data
  • Correct inaccurate information
  • Delete your account and associated records
  • Withdraw consent for optional processing
  • Object to specific uses of your data
  • Raise a grievance with our Data Protection Officer

Policies & contact

Privacy Policy

How we collect, use, and protect personal and health data.

Terms of Service

The rules of the road for using Nevika's products and services.

Data Protection Officer

For privacy questions, data-subject requests, or grievances:

Security disclosure

Found a vulnerability? Please disclose responsibly:

Status

Real-time status of Nevika services and historical incidents.
status.nevika.co (coming soon)

Compliance packet

Enterprise customers can request our security whitepaper, subprocessor list, and audit summaries under NDA.

This page describes Nevika's current controls and roadmap. It is maintained by SEVENVERTEX (Nevika Innovations Private Limited) and is not a substitute for a signed agreement. Certifications marked "in progress" are not yet issued.