Security & Trust

Built to be handed to your security team.

We sell into boardrooms, health systems, utilities and public agencies, so the review is going to be thorough. This page is the short version — the full documentation set is available under NDA.

Compliance

Where we stand today.

We state posture plainly rather than implying more than we hold. Ask us for current evidence and we will send it.

SOC 2 Type II

Audit in progress

Security, availability and confidentiality criteria. Report available under NDA once issued.

HIPAA

Aligned

Administrative, physical and technical safeguards implemented for ClinicOS. BAAs executed with covered entities.

GDPR & UK GDPR

Aligned

Lawful-basis records, data subject request handling, and standard contractual clauses for transfers.

ISO/IEC 27001

Roadmap

Information security management system being formalised against the 2022 revision.

Controls

What is actually implemented.

Data protection

  • AES-256 encryption at rest, TLS 1.3 in transit
  • Customer-managed keys available on enterprise plans
  • Tenant isolation enforced at the storage and compute layer
  • Configurable retention and verified deletion on termination

Access & identity

  • SAML 2.0 and OIDC single sign-on
  • SCIM provisioning and automated deprovisioning
  • Role-based access control down to the record level
  • Mandatory MFA for all Nareth personnel, hardware-backed

Model governance

  • Every inference carries model version, data and policy lineage
  • Permission filtering applied before generation, not after
  • Continuous evaluation with drift and regression alerting
  • Customer data is never used to train shared or third-party models

Operations

  • Independent penetration testing on an annual cadence
  • Vulnerability scanning in CI and in production images
  • Documented incident response with defined notification windows
  • Backup restoration and disaster recovery exercised quarterly

Deployment

Run it where your data is allowed to live.

The same platform and the same controls in all three models. Choosing a stricter boundary costs you deployment time, not capability.

Fastest route to production

Managed cloud

Nareth runs the platform in our cloud with tenant isolation, regional data residency and a standard availability SLA.

Regulated data, existing cloud commitments

Your VPC

The full platform deployed inside your AWS, Azure or GCP account. Your keys, your network boundary, your egress rules.

Critical infrastructure, classified environments

Air-gapped

No outbound connectivity required. Models, updates and evaluation run entirely within your network perimeter.

Support & availability

What we commit to contractually.

Standard

Next business day

Target first response

Business-hours support through the shared portal, quarterly platform release notes and access to the documentation library.

  • Business-hours coverage
  • Shared support portal
  • 99.5% uptime target
  • Quarterly release notes

Enterprise

Most common

4 hours, 24×7 for Sev 1

Target first response

Named technical account manager, priority routing on severity 1 incidents, and a contractual availability commitment.

  • 24×7 Sev 1 coverage
  • Named technical account manager
  • 99.95% uptime SLA
  • Quarterly business review

Mission critical

1 hour, 24×7

Target first response

For deployments where an outage has operational or clinical consequence. Dedicated engineering escalation path and joint runbooks.

  • 24×7 one-hour response
  • Dedicated escalation engineer
  • 99.99% uptime SLA
  • Joint incident runbooks

Subprocessors

Everyone who can touch customer data.

We notify customers before adding a subprocessor. Air-gapped deployments use none of them.

Nareth subprocessors, their purpose and processing region
ProviderPurposeRegion
Amazon Web ServicesCloud infrastructure and storageUnited States, EU
Microsoft AzureCloud infrastructure, optional regionUnited States, EU
SnowflakeAnalytical data warehousingUnited States
TwilioPatient and field messaging deliveryUnited States
StripeBilling and payment processingUnited States

Found something that looks wrong? Report vulnerabilities to security@nareth.ai. We acknowledge within one business day and will not pursue good-faith research.

Start a conversation

Tell us what is slow, expensive, or invisible in your operation.

We will tell you honestly whether AI is the right answer — and if it is, exactly what it would take to get there.