Security & Compliance
Trust is the product.
Health data is the most sensitive data you own. Nevika is engineered from the ground up to protect it — with modern encryption, strict access controls, and clinical governance aligned to HIPAA and India's DPDP Act.
End-to-end encryptionHIPAA-alignedDPDP Act 2023ISO 27001 (in progress)SOC 2 (in progress)
Encryption
Every byte of your data is encrypted, in motion and at rest.
In transit
TLS 1.3 for every request between your device, our edge, and backend services. HSTS enforced. Certificate pinning on native mobile clients.
At rest
AES-256 encryption on all databases, object storage, and backups. Keys are managed with a dedicated KMS and rotated on a fixed schedule.
Field-level
Highly sensitive fields — identifiers, lab values, clinical notes — receive an additional envelope-encryption layer, isolated from application logs.
Access & governance
Least-privilege access
Role-based access control with row-level security in the database. Production access is time-bound, reviewed, and fully audit-logged.
Authentication
Multi-factor authentication for all clinician and staff accounts. Passwords hashed with modern KDFs. Sessions rotated on privilege change.
Audit trail
Every read and write to identifiable health data is logged with actor, purpose, and timestamp. Logs are tamper-evident and retained per regulation.
Secure development
Peer code review, automated dependency scanning, and secret scanning on every change. Regular third-party penetration testing.
Data handling
Your data is used to serve you — not to train third-party foundation models.
Purpose limitation
We collect only what is needed to provide care coordination, triage, and record-keeping. No sale of personal or health data, ever.
Model boundaries
Prompts and clinical content sent to AI providers are stripped of direct identifiers where possible, and are excluded from provider training by contract.
Retention & deletion
You can export or delete your data at any time. Backups roll off on a defined schedule. Legal-hold data is isolated and minimized.
Data residency
Indian user data is stored in Indian regions where feasible. Cross-border transfers use standard contractual clauses and equivalent safeguards.
Subprocessors
We use a small set of vetted subprocessors for hosting, email, analytics, and AI inference. A current list is available on request.
Breach response
Documented incident-response playbook with defined severity levels, on-call rotation, and regulator / user notification windows aligned to HIPAA and DPDP.
Compliance
HIPAA-aligned
Nevika's controls are designed against the HIPAA Security Rule — administrative, physical, and technical safeguards for protected health information. BAAs are available for eligible clinical partners in the US.
DPDP Act 2023 (India)
We operate as a Data Fiduciary under India's Digital Personal Data Protection Act — with consent-first collection, purpose limitation, grievance handling, and rights of access, correction, and erasure.
GDPR-ready
For EU users, we honor data-subject rights and use lawful bases consistent with the GDPR, including for cross-border transfers.
Certifications
ISO 27001 and SOC 2 Type II readiness programs are underway. Progress reports are shared with enterprise customers under NDA.
Your rights
- Access a copy of your health data
- Correct inaccurate information
- Delete your account and associated records
- Withdraw consent for optional processing
- Object to specific uses of your data
- Raise a grievance with our Data Protection Officer
Policies & contact
Privacy Policy
How we collect, use, and protect personal and health data.
Terms of Service
The rules of the road for using Nevika's products and services.
Data Protection Officer
For privacy questions, data-subject requests, or grievances:
Security disclosure
Found a vulnerability? Please disclose responsibly:
Status
Real-time status of Nevika services and historical incidents.
status.nevika.co (coming soon)
Compliance packet
Enterprise customers can request our security whitepaper, subprocessor list, and audit summaries under NDA.
This page describes Nevika's current controls and roadmap. It is maintained by SEVENVERTEX (Nevika Innovations Private Limited) and is not a substitute for a signed agreement. Certifications marked "in progress" are not yet issued.