Trust
The Architecture We Intend to Build and Verify.
Nuraflow is pre-launch. This page describes the security and privacy architecture the product is intended to follow. It is not a claim that every control has been implemented, independently audited or certified. Verified implementation status and supporting evidence will be published as they become available.
The Closed Loop
Protection Follows the Record.
The intended control model begins before storage and continues through every use, audit, export and disposition. Each stage must leave evidence that can be inspected.
- 01
Capture
Collect only through an approved application, form, import or integration.
Evidence: Source, consent and timestamp
- 02
Validate
Check identity, required fields, format and workflow permissions before use.
Evidence: Validation and review event
- 03
Store
Protect records with tenant context, encryption and controlled retention.
Evidence: Encrypted record and version
- 04
Use
Authorize the role, purpose and minimum necessary view for the task.
Evidence: Scoped access event
- 05
Audit
Record sensitive reads and material changes for review and investigation.
Evidence: Protected audit trail
- 06
Export or Delete
Apply agency authorization, retention requirements and a documented disposition.
Evidence: Export or deletion record
Closed Loop
Disposition Evidenced
Authorization, retention basis, action, timestamp and accountable actor remain inspectable.
Sensitive information is intended to stay out of URLs, general analytics, unfiltered diagnostic logs and error messages. Those edges are treated as data boundaries, not harmless text fields.
Access Model
A Login Is Not Permission to See Everything.
The exact production matrix will be configurable by agency and responsibility. This representative model shows the intended principle: role, tenant, assignment and purpose all matter, and sensitive access produces an audit event.
| Record or Action | Field Staff | Clinician | Scheduler | Billing | System |
|---|---|---|---|---|---|
| Assigned visit and tasks | Scoped | Allowed | Scoped | Denied | Audited |
| Clinical note | Scoped | Allowed | Denied | Scoped | Audited |
| Full schedule | Denied | Scoped | Allowed | Denied | Audited |
| Claim and remittance | Denied | Scoped | Scoped | Allowed | Audited |
| Employee screening | Denied | Denied | Denied | Denied | Restricted |
| Audit history | Denied | Scoped | Scoped | Scoped | Protected |
Control Register
Controls Need an Enforcement Point and Evidence.
| Control | Scope | Enforcement Point | Evidence Expected |
|---|---|---|---|
| Encryption | Sensitive data in transit and at rest | Transport, storage and managed key boundaries | Configuration and key-management records |
| Identity and Access | Workforce, client and system access | Role, tenant and record authorization | Access reviews and authentication logs |
| Tenant Isolation | Every agency-owned record | Application, query, storage and test layers | Isolation tests and tenant-aware logs |
| Auditability | Sensitive reads and material record changes | Application and infrastructure events | Protected audit and monitoring records |
| Data Minimization | URLs, analytics, logs and error messages | Development standards and telemetry filtering | Reviews, tests and scanning results |
| Backup and Recovery | Production records and critical configuration | Encrypted backups and tested restoration | Backup status and recovery exercises |
| Subprocessor Review | Services that could process sensitive data | Vendor approval and contractual controls | Risk review and BAA where applicable |
| Incident Response | Security, privacy and availability events | Detection, triage, containment and notification | Runbooks, exercises and incident record |
AWS and AI Boundary
Cloud Eligibility Does Not Configure the Cloud for You.
The intended production footprint uses HIPAA-eligible AWS services under the AWS shared-responsibility model and a Business Associate Agreement where required. Amazon Bedrock is intended to provide the governed model access layer for AI workflows. Service eligibility does not make an application compliant by itself; configuration, access, data flow, monitoring and operating practice remain Nuraflow responsibilities.
- Encrypt model requests and connected data paths
- Limit model access through role and tenant context
- Keep generated content visibly identified as a draft
- Retain source context and human approval for consequential outputs
- Prevent AI from making clinical, legal, employment or policy decisions
Assurance Status
Internal Assurance Readiness Plans Are Pending Approval.
- HIPAA
- Nuraflow's internal HIPAA safeguard readiness plan is pending approval. HIPAA has no government certification, and no third-party assurance has been completed.
- SOC 2
- Nuraflow's internal SOC 2 readiness plan is pending approval. No independent examination has been completed.
- ISO 27001
- Nuraflow's internal ISO 27001 readiness plan is pending approval. No certification has been obtained.
- Customer Evidence
- Nuraflow is pre-launch and publishes no customer security results it has not earned.
Ask Directly
Security Questions Should Receive Specific Answers.
Ask about the architecture, enforcement point, expected evidence and current assurance status behind a control.