Trust Center

Built for healthcare. Audited by design.

Every record attributed, every action logged, every tenant isolated. Here is how Nem protects clinic data, and what we sign before any patient data reaches us.

Last updated August 1, 2026

HIPAA-aligned architectureBAA offered to every clinic2FA + fail-closed access controlSOC 2 planned

Fail-closed access control

Role-based permissions that deny by default. Every page verifies your session, role, clinic, and record existence on the server. A URL never grants access.

Complete audit trail

Every create, change, and deletion is attributed and timestamped. Nothing is silently removed; records are retired, never erased without a trace.

Encryption and 2FA

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Two-factor authentication and modern password standards protect every account.

Tenant isolation

Each clinic is a hard data boundary keyed on clinicId. Multi-clinic organizations see only what their roles allow, per clinic.

PHI-free email policy

Email never carries Protected Health Information. An automated guard blocks any outbound message that looks like it might contain PHI.

Retention and deletion

Your data stays available for 30 days after termination so you can export it, then we delete it. Audit logs are kept for at least 6 years. Deletion is a documented process backed by schema-enforced soft deletion, not an automated purge engine.

Subprocessors

Vendors that process data on our behalf. A Business Associate Agreement is executed with every PHI-touching subprocessor before any live patient data is onboarded.

Vendor agreements. BAAs are executed progressively ahead of any PHI, not all at once. The status column below is the current position for each vendor, and executed agreements and their records are retained. This list was last reviewed on August 1, 2026.

Where our people are. Nem is operated with the support of its affiliate NEMSOL (Pvt) Ltd (CUIN 0342731), registered in Pakistan. Named engineering and support personnel of that affiliate access the platform. Access to Protected Health Information is permitted only under an intercompany Business Associate Agreement executed before any PHI is processed in production, and we will tell customers before that arrangement changes.

VendorPurposeTouches PHIBAA status
Retell AIVoice infrastructureYes (at go-live)BAA executed (Jul 2026)
Google WorkspaceBusiness email and documentsPossible; BAA executedBAA + CDPA executed (Jul 2026)
AWSFile storage, email transportYes (at go-live)BAA executed at account setup
VercelApplication hostingYes (at go-live)BAA executed at PHI go-live
NeonDatabaseYes (at go-live)BAA executed at PHI go-live
NEMSOL (Pvt) LtdEngineering and support personnel (Pakistan)Yes (at go-live)Intercompany BAA executed before any PHI access
StripeSubscription billing and paymentsNo, billing data onlyNot required; PHI-free by design
Cloudflare TurnstileBot protection on sign-in and sign-upNo, IP address and challenge token onlyNot required; never in a PHI path
ResendTransactional emailNo, PHI-free by policyNot required
PostHogProduct analyticsNo, no patient dataNot required

Documents

Honest framing. Nem is in beta. Every demo environment runs on synthetic data only; no real patient data is accepted until your BAA and our vendor BAAs are in place. HIPAA has no official certification, and no organization can be certified HIPAA compliant, so we do not claim one. What we can say is that our architecture is built to the HIPAA Security Rule safeguards, our self-attestation is in progress, and SOC 2 is planned rather than held. We will never claim a certification we do not have. The statements above describe our architecture and practices.