HIPAA & BAA
Every product is architected for HIPAA, and we sign a Business Associate Agreement on every client engagement that involves protected health information.
Security and compliance aren't a page we added — they're the baseline every NuScript product is engineered to, the same standard across Dictra and Zera.
Running a security review or need documentation for due diligence? We're glad to share what your team needs, including our subprocessor list, under NDA.
Every product is architected for HIPAA, and we sign a Business Associate Agreement on every client engagement that involves protected health information.
Independently audited controls spanning security, availability, and confidentiality — Type I certified, with a Type II examination underway. Evidence for your vendor due diligence, not just assurances.
Data is encrypted in transit and at rest, using industry-standard protocols across every service and storage layer.
Each client's data is isolated, with role-based access controls so people only reach what they're authorized to.
Our products run on reputable US cloud infrastructure, with a limited, vetted set of subprocessors engaged under HIPAA-consistent terms.
Access and activity are logged and timestamped, so there's a clear, reviewable record across the documentation and revenue workflows.
Tell us what your security and compliance process needs, and we'll get you the right documentation.