Skip to content

Privacy controls

Essential

Required for security and remembering your privacy choices. These cannot be switched off.

Always on

Trust

The Architecture We Intend to Build and Verify.

Nuraflow is pre-launch. This page describes the security and privacy architecture the product is intended to follow. It is not a claim that every control has been implemented, independently audited or certified. Verified implementation status and supporting evidence will be published as they become available.

The Closed Loop

Protection Follows the Record.

The intended control model begins before storage and continues through every use, audit, export and disposition. Each stage must leave evidence that can be inspected.

  1. 01

    Capture

    Collect only through an approved application, form, import or integration.

    Evidence: Source, consent and timestamp

  2. 02

    Validate

    Check identity, required fields, format and workflow permissions before use.

    Evidence: Validation and review event

  3. 03

    Store

    Protect records with tenant context, encryption and controlled retention.

    Evidence: Encrypted record and version

  4. 04

    Use

    Authorize the role, purpose and minimum necessary view for the task.

    Evidence: Scoped access event

  5. 05

    Audit

    Record sensitive reads and material changes for review and investigation.

    Evidence: Protected audit trail

  6. 06

    Export or Delete

    Apply agency authorization, retention requirements and a documented disposition.

    Evidence: Export or deletion record

Closed Loop

Disposition Evidenced

Authorization, retention basis, action, timestamp and accountable actor remain inspectable.

Sensitive information is intended to stay out of URLs, general analytics, unfiltered diagnostic logs and error messages. Those edges are treated as data boundaries, not harmless text fields.

Access Model

A Login Is Not Permission to See Everything.

The exact production matrix will be configurable by agency and responsibility. This representative model shows the intended principle: role, tenant, assignment and purpose all matter, and sensitive access produces an audit event.

Record or ActionField StaffClinicianSchedulerBillingSystem
Assigned visit and tasksScopedAllowedScopedDeniedAudited
Clinical noteScopedAllowedDeniedScopedAudited
Full scheduleDeniedScopedAllowedDeniedAudited
Claim and remittanceDeniedScopedScopedAllowedAudited
Employee screeningDeniedDeniedDeniedDeniedRestricted
Audit historyDeniedScopedScopedScopedProtected

Control Register

Controls Need an Enforcement Point and Evidence.

ControlScopeEnforcement PointEvidence Expected
EncryptionSensitive data in transit and at restTransport, storage and managed key boundariesConfiguration and key-management records
Identity and AccessWorkforce, client and system accessRole, tenant and record authorizationAccess reviews and authentication logs
Tenant IsolationEvery agency-owned recordApplication, query, storage and test layersIsolation tests and tenant-aware logs
AuditabilitySensitive reads and material record changesApplication and infrastructure eventsProtected audit and monitoring records
Data MinimizationURLs, analytics, logs and error messagesDevelopment standards and telemetry filteringReviews, tests and scanning results
Backup and RecoveryProduction records and critical configurationEncrypted backups and tested restorationBackup status and recovery exercises
Subprocessor ReviewServices that could process sensitive dataVendor approval and contractual controlsRisk review and BAA where applicable
Incident ResponseSecurity, privacy and availability eventsDetection, triage, containment and notificationRunbooks, exercises and incident record

AWS and AI Boundary

Cloud Eligibility Does Not Configure the Cloud for You.

The intended production footprint uses HIPAA-eligible AWS services under the AWS shared-responsibility model and a Business Associate Agreement where required. Amazon Bedrock is intended to provide the governed model access layer for AI workflows. Service eligibility does not make an application compliant by itself; configuration, access, data flow, monitoring and operating practice remain Nuraflow responsibilities.

  • Encrypt model requests and connected data paths
  • Limit model access through role and tenant context
  • Keep generated content visibly identified as a draft
  • Retain source context and human approval for consequential outputs
  • Prevent AI from making clinical, legal, employment or policy decisions

Assurance Status

Internal Assurance Readiness Plans Are Pending Approval.

HIPAA
Nuraflow's internal HIPAA safeguard readiness plan is pending approval. HIPAA has no government certification, and no third-party assurance has been completed.
SOC 2
Nuraflow's internal SOC 2 readiness plan is pending approval. No independent examination has been completed.
ISO 27001
Nuraflow's internal ISO 27001 readiness plan is pending approval. No certification has been obtained.
Customer Evidence
Nuraflow is pre-launch and publishes no customer security results it has not earned.

Ask Directly

Security Questions Should Receive Specific Answers.

Ask about the architecture, enforcement point, expected evidence and current assurance status behind a control.