NuScript Systems
§ Security & trust

Built to healthcare's bar.

Security and compliance aren't a page we added — they're the baseline every NuScript product is engineered to, the same standard across Dictra and Zera.

Control framework

One security baseline. Every product.

Running a security review or need documentation for due diligence? We're glad to share what your team needs, including our subprocessor list, under NDA.

HIPAA & BAA

Every product is architected for HIPAA, and we sign a Business Associate Agreement on every client engagement that involves protected health information.

SOC 2 Type I

Independently audited controls spanning security, availability, and confidentiality — Type I certified, with a Type II examination underway. Evidence for your vendor due diligence, not just assurances.

Encryption everywhere

Data is encrypted in transit and at rest, using industry-standard protocols across every service and storage layer.

Tenant isolation & access control

Each client's data is isolated, with role-based access controls so people only reach what they're authorized to.

Secure US infrastructure

Our products run on reputable US cloud infrastructure, with a limited, vetted set of subprocessors engaged under HIPAA-consistent terms.

Audit trails

Access and activity are logged and timestamped, so there's a clear, reviewable record across the documentation and revenue workflows.

Independently verified
SOC 2 Type I
Certified · Type II in progress
HIPAA
Architected for compliance
BAA
On every engagement
Vendor review

Reviewing us as a vendor?

Tell us what your security and compliance process needs, and we'll get you the right documentation.