TESTING MODE — Payment processing is disabled. Not for production use.
SOC 2 Type II Certified · HIPAA Compliant

Security Built for Healthcare

Patient data is your highest responsibility. Ours is making sure it never leaves your control — even when AI is involved.

Request Security Documentation

Security Architecture

Six layers of protection — not as checkboxes, but as non-negotiable design requirements.

PHI Never Reaches the LLM

Before any data enters an AI model, Navaryn's application layer scans for all 18 HIPAA-defined PHI identifiers and replaces them with opaque, non-reversible tokens (e.g., [TOK_NAME_001]). The original values are stored encrypted in your organization's isolated data store. The AI reasons entirely on de-identified tokens.

Encryption at Rest and in Transit

All data stored in Navaryn is encrypted using AES-256. All data in transit is protected by TLS 1.3. Encryption keys are unique per organization and rotated on a 90-day cycle. Keys are never accessible to Navaryn staff.

Isolated Tenant Architecture

Each organization operates in a fully isolated data environment. There is no shared storage, shared compute, or cross-tenant data access. Row-level security is enforced at the database layer in addition to application-layer access controls.

Mandatory Human Review

Every AI-generated compliance document — policies, breach notifications, risk assessments, physician queries — enters a structured approval queue and cannot be finalized without explicit human approval. This is enforced at the system level, not policy.

Immutable Audit Trails

Every agent interaction, approval action, document modification, and re-identification event is written to an append-only audit log. Logs cannot be modified or deleted, even by administrators. Logs are exportable in NIST-compatible formats for regulatory investigations.

Access Control & Authentication

Role-based access control (RBAC) with least-privilege defaults. Multi-factor authentication (MFA) is available on all plans and required on Team+. Enterprise plans support SSO/SAML integration with your existing identity provider.

Re-Identification Control Flow

When a credentialed user legitimately needs to view original PHI, every step is controlled and recorded.

  1. 1

    Re-identification requires an explicit, logged request by an authorized user

  2. 2

    The requesting user's identity, role, and stated purpose are recorded

  3. 3

    A supervisor approval step is triggered for any PHI re-identification (configurable)

  4. 4

    The original value is decrypted and displayed only within the secure session

  5. 5

    The re-identification event is written to the immutable audit log

  6. 6

    Session data is not cached and expires on session end

Compliance & Certifications

HIPAA

Navaryn's architecture is designed to satisfy HIPAA Security Rule requirements (45 CFR Part 164). Business Associate Agreements (BAAs) are available on Team and Enterprise plans.

SOC 2 Type II

Navaryn undergoes annual SOC 2 Type II audits covering Security, Availability, and Confidentiality trust service criteria. Reports available under NDA.

Data Residency

All customer data is stored and processed within the United States. Enterprise customers may request dedicated infrastructure in a specific AWS region.

Penetration Testing

Third-party penetration tests are conducted annually by an independent security firm. Results are addressed before the next release cycle.

Questions About Our Security Posture?

We're happy to share our SOC 2 report, complete our security questionnaire, or schedule a technical deep-dive with your security team.

Contact Security Team