Security & compliance
Built privacy-first for special-category health data.
Fertility data is among the most sensitive personal data there is. Nidus treats security and privacy as the foundation of the platform: isolation, secret handling and data residency are designed in, not bolted on.
Multi-tenant isolation
Every clinic is a separate tenant with row-level security enforced in the database. You can only ever read and write your own data. Isolation is structural, not a filter that code has to remember.
Write-only credentials
Connection secrets are stored in an encrypted vault and are never returned to the interface. The cockpit shows only which secrets are set, never their values.
On-premise egress agent
For IP-whitelisted or on-premise systems like VRepro, an outbound-only agent runs inside the clinic and executes calls locally. The clinic opens no inbound port, and patient data and credentials stay on-premise.
PII kept out of the cockpit
Raw webhook payloads are held in a service-role-only queue that the interface cannot read. Observability runs on a separate, sanitised event log. GDPR by design.
Append-only audit log
Security-relevant actions (who set a secret, changed a connection or toggled a workflow) are recorded in an append-only trail for accountability and audits.
Retention & erasure
Raw data is purged on a schedule so it doesn't accumulate, supporting storage-limitation and right-to-erasure obligations under GDPR.
Data residency
EU data, kept in the EU.
For EU clinics, Nidus pins data and secrets to EU infrastructure, with a documented data processing agreement and subprocessor list, decided before any real patient data is onboarded.
The credential principle
For on-premise systems, credentials can stay entirely inside the clinic: the egress agent holds them locally and Nidus never stores them centrally. The result is a stronger residency posture than a typical cloud integration. Your most sensitive data never leaves the building.
Compliance
Building toward the standards enterprise buyers require.
Nidus is being built to satisfy the frameworks fertility groups and their security teams expect. Controls above are the evidence these certifications are designed to formalise.
ISO 27001
Information security management
The ISMS backbone: policies, risk register, access reviews and vendor management.
ISO 27701
Privacy information management
Privacy controls and data governance for special-category health data.
SOC 2 Type II
Trust services criteria
Continuous evidence of security, availability and confidentiality controls over time.
ISO 27001 is in place. ISO 27701 and SOC 2 Type II are in progress. The controls described on this page are implemented in the platform today. Ask sales for current documentation.
Send us your security questionnaire.
We're happy to walk your security and data-protection teams through our architecture, controls and data-processing terms.