Trust & Safety

Your Security Is Our Priority

Health data is the most sensitive information you can hand to a company. So this page sets out exactly what protects it today, and what we are still building — including fully homomorphic encryption, which will let us analyse medical records for your care team without ever decrypting them.

In Place Today

Protections that are live on the platform right now.

Encryption in Transit and at Rest

All traffic runs over TLS. Health data is stored on managed database infrastructure with AES-256 encryption at rest, and database connections require TLS with channel binding.

Passwordless, Verified Sign-In

Accounts are verified by one-time code sent to your email rather than a reusable password, so there is no stored password to leak or reuse across services.

Role-Based Access Control

Patients, doctors and clinics each see only the data their role permits. Provider accounts are gated behind registration and review before they can access patient-facing features.

Certified Cloud Infrastructure

The platform runs on managed cloud providers that hold ISO 27001 and SOC 2 Type II certification for their own operations, with automated backups and redundant storage.

Your Data Is Never Sold

We do not sell health data, and we do not share it with third parties for advertising. Data is used to deliver the service you asked for, and to improve it with your consent.

Responsible Disclosure

Security researchers can report vulnerabilities directly to our team. We commit to acknowledging every report and to not pursuing legal action against good-faith research.

Building Ahead of Beta

Work in progress, stated plainly. These are commitments we are engineering toward before beta launch — not capabilities we claim today.

In progress

Fully Homomorphic Encryption

We are building our analysis pipeline around fully homomorphic encryption (FHE), which allows computation to run directly on encrypted data. The goal: deliver insights to your healthcare provider without our systems ever decrypting the underlying medical record.

In progress

Regional Data Residency

Health data currently resides in our provider's United States region. Ahead of general availability we are moving to regional hosting, so data for each market is stored under the data-protection regime that governs it.

In progress

Independent Security Assessment

We intend to undergo third-party security assessment and pursue formal certification appropriate to each market we operate in, rather than self-declaring compliance.

In progress

Continuous Monitoring and Incident Response

A documented incident-response process with defined notification timelines, plus continuous monitoring and anomaly detection, are being put in place ahead of handling live patient data at scale.

Standards Guiding Our Design

We build against the requirements of the regimes that govern health data in the markets we are entering.

HIPAA
Health data protection (US)
GDPR
EU data protection regulation
PDPA
Personal Data Protection Act (Malaysia)
PDP Law
Personal data protection (Indonesia)
ISO 27001
Information security management
SOC 2
Service organization controls

To be clear: eazyCare.Ai is pre-launch and does not currently hold certification against these standards. They describe the requirements we design and build against, and the assessments we intend to pursue as the platform approaches general availability. We would rather tell you exactly where we stand than imply otherwise.

Responsible Disclosure

We encourage security researchers to report vulnerabilities responsibly. If you discover a security issue, please email us at security@eazycare.ai. We commit to acknowledging reports within 48 hours and resolving critical issues within 7 days.

We do not pursue legal action against good-faith security researchers

Security Questions?

Our security team is here to help. Reach out anytime for questions about our security practices or to report concerns.

Contact Security Team