Now in production with VRepro clinics.See the integration

Security & compliance

Built privacy-first for special-category health data.

Fertility data is among the most sensitive personal data there is. Nidus treats security and privacy as the foundation of the platform: isolation, secret handling and data residency are designed in, not bolted on.

Multi-tenant isolation

Every clinic is a separate tenant with row-level security enforced in the database. You can only ever read and write your own data. Isolation is structural, not a filter that code has to remember.

Write-only credentials

Connection secrets are stored in an encrypted vault and are never returned to the interface. The cockpit shows only which secrets are set, never their values.

On-premise egress agent

For IP-whitelisted or on-premise systems like VRepro, an outbound-only agent runs inside the clinic and executes calls locally. The clinic opens no inbound port, and patient data and credentials stay on-premise.

PII kept out of the cockpit

Raw webhook payloads are held in a service-role-only queue that the interface cannot read. Observability runs on a separate, sanitised event log. GDPR by design.

Append-only audit log

Security-relevant actions (who set a secret, changed a connection or toggled a workflow) are recorded in an append-only trail for accountability and audits.

Retention & erasure

Raw data is purged on a schedule so it doesn't accumulate, supporting storage-limitation and right-to-erasure obligations under GDPR.

Data residency

EU data, kept in the EU.

For EU clinics, Nidus pins data and secrets to EU infrastructure, with a documented data processing agreement and subprocessor list, decided before any real patient data is onboarded.

The credential principle

For on-premise systems, credentials can stay entirely inside the clinic: the egress agent holds them locally and Nidus never stores them centrally. The result is a stronger residency posture than a typical cloud integration. Your most sensitive data never leaves the building.

Compliance

Building toward the standards enterprise buyers require.

Nidus is being built to satisfy the frameworks fertility groups and their security teams expect. Controls above are the evidence these certifications are designed to formalise.

ISO 27001

Certified

Information security management

The ISMS backbone: policies, risk register, access reviews and vendor management.

ISO 27701

In progress

Privacy information management

Privacy controls and data governance for special-category health data.

SOC 2 Type II

In progress

Trust services criteria

Continuous evidence of security, availability and confidentiality controls over time.

ISO 27001 is in place. ISO 27701 and SOC 2 Type II are in progress. The controls described on this page are implemented in the platform today. Ask sales for current documentation.

Send us your security questionnaire.

We're happy to walk your security and data-protection teams through our architecture, controls and data-processing terms.