Security
Nestera builds software that touches sensitive health data, so security isn't a page we bolted on — it's how the platform is built. Here's a plain-language summary of how we protect it.
Compliance
We operate as a HIPAA business associate under signed Business Associate Agreements with our health system partners. Our SOC 2 Type II examination is currently in progress.
Our infrastructure runs on AWS, under an executed Business Associate Agreement covering all production systems.
How your data is protected
Data is encrypted in transit and at rest. Each customer's data is encrypted under that customer's own dedicated encryption key, never a key shared across customers, so no customer's data can be exposed through another customer's key.
Backups are encrypted, taken daily, and retained for at least 90 days, with copies stored in a separate region for durability.
When a contract ends, we destroy the encryption keys tied to that customer's data, which renders it permanently unreadable.
How access is controlled
Access to customer data follows the principle of least privilege: our team can reach only what their role requires, every production access grant is just-in-time and requires multi-factor authentication, and access rights are reviewed at least quarterly. In the rare case an engineer needs emergency access to diagnose a live issue, that access is read-only by default, requires approval from a second person, and is reviewed within one business day.
How we monitor and respond
We monitor our systems continuously for security-relevant activity, and every access to patient data is logged and retained for a minimum of six years. If a security incident affects your data, we commit to notifying you within 24 hours of identifying it, and within 72 hours for a confirmed or suspected breach of protected health information — well inside the legal requirement.
How the platform stays available
Our infrastructure runs across multiple availability zones with automatic failover, and our entire environment can be rebuilt from code if something goes seriously wrong. We maintain a documented business continuity and disaster recovery plan, tested at least once a year.
Keeping a human in the loop
Nestera's risk predictions and recommendations are built to support clinical judgment, not replace it. Every recommendation our platform makes can be accepted, adjusted, or overridden by the care team using it, and every action is logged.
Reporting a concern
If you've found a security issue or want to report a concern, email us at founders@nesterahealth.com. We take reports seriously and will respond promptly.