ProductSolutionsROIPricingResourcesBook a walkthrough
ProductSolutionsROIPricingResourcesBook a walkthrough

Trust Center

Security, privacy,
and compliance.

Nuvae handles protected health information every day. This page describes how we secure it, who's accountable for it, and how to get the documentation your security or compliance team needs.

HIPAA compliantSOC 2 Type II certifiedBAA signed with every customerOn-premise available

Security

Secure infrastructure

Hosted on leading cloud infrastructure with network segmentation, hardened services, backups, and disaster-recovery mechanisms built for healthcare data.

Encryption & data protection

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent), with key management following cloud-provider and industry best practices.

Access control & identity

Role-based access control (RBAC) and least-privilege principles across every internal and customer-facing system, with multi-factor authentication for all personnel with production access.

Monitoring & incident response

Centralized logging of application and infrastructure events, continuous monitoring for anomalies, and a documented incident-response process — including HIPAA breach-notification obligations where applicable.

Compliance

HIPAA compliant

Nuvae operates as a HIPAA-compliant Business Associate and signs a Business Associate Agreement (BAA) with every customer. PHI is used only as permitted by HIPAA, the BAA, and customer instructions — never for Nuvae's own marketing or third-party advertising.

SOC 2 Type II certified

Nuvae has completed SOC 2 Type II certification across the Security, Availability, and Confidentiality Trust Services Criteria. The report and supporting security artifacts are available to customers under NDA.

Deployment options

Nuvae runs cloud-hosted by default. For health systems with strict data-residency or network-isolation requirements, an on-premise deployment is available — contact us to scope it.

AI & human oversight

  • • Every AI-generated output — a rate match, a denial score, a drafted appeal — is reviewable and traceable back to the contract, policy, or remittance line that produced it.
  • • PHI is never used to train third-party foundation models. De-identified, aggregated data may be used to improve Nuvae's own models, only where permitted by contract and law.
  • • High-confidence outputs can automate; low-confidence or ambiguous cases route to human review rather than guessing.
  • • Customers remain responsible for final billing and clinical decisions — Nuvae's outputs support that judgment, they don't replace it.

Request documentation

SOC 2 Type II report, security questionnaire responses, and a signed BAA are available on request. Contact contact@nuvae.ai — include your organization name and what you need for procurement or security review.

Report a security concern

If you believe you've found a security vulnerability affecting Nuvae, email contact@nuvae.ai with a description of the issue, steps to reproduce it, and your contact details — please don't include PHI in the report itself.

Talk to our security teamRead the Privacy Policy
— revenue protection · © 2026
ProductSolutionsROIPricing
CustomersResourcesAbout usCareersContact
Trust CenterPrivacy PolicyTerms of Service
HIPAA compliant · SOC 2 Type II certified · BAA available on request