Your Security Is Our Priority
Health data is the most sensitive information you can hand to a company. So this page sets out exactly what protects it today, and what we are still building — including fully homomorphic encryption, which will let us analyse medical records for your care team without ever decrypting them.
In Place Today
Protections that are live on the platform right now.
Encryption in Transit and at Rest
All traffic runs over TLS. Health data is stored on managed database infrastructure with AES-256 encryption at rest, and database connections require TLS with channel binding.
Passwordless, Verified Sign-In
Accounts are verified by one-time code sent to your email rather than a reusable password, so there is no stored password to leak or reuse across services.
Role-Based Access Control
Patients, doctors and clinics each see only the data their role permits. Provider accounts are gated behind registration and review before they can access patient-facing features.
Certified Cloud Infrastructure
The platform runs on managed cloud providers that hold ISO 27001 and SOC 2 Type II certification for their own operations, with automated backups and redundant storage.
Your Data Is Never Sold
We do not sell health data, and we do not share it with third parties for advertising. Data is used to deliver the service you asked for, and to improve it with your consent.
Responsible Disclosure
Security researchers can report vulnerabilities directly to our team. We commit to acknowledging every report and to not pursuing legal action against good-faith research.
Building Ahead of Beta
Work in progress, stated plainly. These are commitments we are engineering toward before beta launch — not capabilities we claim today.
Fully Homomorphic Encryption
We are building our analysis pipeline around fully homomorphic encryption (FHE), which allows computation to run directly on encrypted data. The goal: deliver insights to your healthcare provider without our systems ever decrypting the underlying medical record.
Regional Data Residency
Health data currently resides in our provider's United States region. Ahead of general availability we are moving to regional hosting, so data for each market is stored under the data-protection regime that governs it.
Independent Security Assessment
We intend to undergo third-party security assessment and pursue formal certification appropriate to each market we operate in, rather than self-declaring compliance.
Continuous Monitoring and Incident Response
A documented incident-response process with defined notification timelines, plus continuous monitoring and anomaly detection, are being put in place ahead of handling live patient data at scale.
Standards Guiding Our Design
We build against the requirements of the regimes that govern health data in the markets we are entering.
To be clear: eazyCare.Ai is pre-launch and does not currently hold certification against these standards. They describe the requirements we design and build against, and the assessments we intend to pursue as the platform approaches general availability. We would rather tell you exactly where we stand than imply otherwise.
Responsible Disclosure
We encourage security researchers to report vulnerabilities responsibly. If you discover a security issue, please email us at security@eazycare.ai. We commit to acknowledging reports within 48 hours and resolving critical issues within 7 days.
Security Questions?
Our security team is here to help. Reach out anytime for questions about our security practices or to report concerns.
Contact Security Team