Trust Center
Security, privacy,
and compliance.
Nuvae handles protected health information every day. This page describes how we secure it, who's accountable for it, and how to get the documentation your security or compliance team needs.
Security
Hosted on leading cloud infrastructure with network segmentation, hardened services, backups, and disaster-recovery mechanisms built for healthcare data.
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent), with key management following cloud-provider and industry best practices.
Role-based access control (RBAC) and least-privilege principles across every internal and customer-facing system, with multi-factor authentication for all personnel with production access.
Centralized logging of application and infrastructure events, continuous monitoring for anomalies, and a documented incident-response process — including HIPAA breach-notification obligations where applicable.
Compliance
Nuvae operates as a HIPAA-compliant Business Associate and signs a Business Associate Agreement (BAA) with every customer. PHI is used only as permitted by HIPAA, the BAA, and customer instructions — never for Nuvae's own marketing or third-party advertising.
Nuvae has completed SOC 2 Type II certification across the Security, Availability, and Confidentiality Trust Services Criteria. The report and supporting security artifacts are available to customers under NDA.
Nuvae runs cloud-hosted by default. For health systems with strict data-residency or network-isolation requirements, an on-premise deployment is available — contact us to scope it.
AI & human oversight
- • Every AI-generated output — a rate match, a denial score, a drafted appeal — is reviewable and traceable back to the contract, policy, or remittance line that produced it.
- • PHI is never used to train third-party foundation models. De-identified, aggregated data may be used to improve Nuvae's own models, only where permitted by contract and law.
- • High-confidence outputs can automate; low-confidence or ambiguous cases route to human review rather than guessing.
- • Customers remain responsible for final billing and clinical decisions — Nuvae's outputs support that judgment, they don't replace it.
Request documentation
SOC 2 Type II report, security questionnaire responses, and a signed BAA are available on request. Contact contact@nuvae.ai — include your organization name and what you need for procurement or security review.
Report a security concern
If you believe you've found a security vulnerability affecting Nuvae, email contact@nuvae.ai with a description of the issue, steps to reproduce it, and your contact details — please don't include PHI in the report itself.