Trust Center

Security and compliance at Nem

How Nem protects clinic data, what is in place today, and what is still in progress. An item is marked In place only when it is live in production today.

Last reviewed September 24, 2026

Compliance

Each item carries one of three statuses.

Controls

A control with no status is in place today.

Infrastructure security

  • Production is hosted in the United States on Google Cloud (us-central1).
  • The production database has no public IP; an enforced organization policy keeps it on the private network.
  • Encryption in transit (TLS) on every connection, and at rest with Google-managed keys as a platform default.
  • Least-privilege cloud access: per-secret permissions, and long-lived service account keys disabled by policy.
  • Automated daily database backups with point-in-time recovery.
  • A full restore drill that proves and times recovery from backup.In progress
  • Uptime monitoring with real-time alerting.In progress

Product security

  • Two-factor authentication (authenticator app) is available to users; requiring it on every account is not yet switched on.In progress
  • Role-based access scoped to each clinic, enforced on the server rather than only hidden in the interface.
  • Sign-in protection: account lockout and rate-limited login attempts.

Data and privacy

  • Clinic data isolation: every database query is checked for a clinic boundary. Most core data models refuse an unscoped query today; the rest are being switched over in stages.In progress
  • Audit log of access to and changes on patient records; masking coverage and failure alerting are being extended.In progress
  • Your data stays available for 30 days after termination so you can export it, then we delete it. Audit logs are kept for at least 6 years. Deletion is a documented process backed by schema-enforced soft deletion, not an automated purge engine.
  • Clinic-wide bulk data export. Until it ships, automatic deletion stays off by design.In progress
  • Email never carries patient information; an automated check blocks any outbound message that looks like it might.

Organizational security

  • A Business Associate Agreement with every clinic, signed before any patient data is processed.
  • Vendor BAAs executed with Retell AI, Google Workspace, AWS and Google Cloud.
  • Breach notification to affected clinics no later than five (5) business days after discovery.
  • Incident response plan rewritten for our current cloud environment.In progress
  • Documented security policies and workforce security training.In progress

AI and voice

  • AI model calls pass through one gateway that refuses any provider not confirmed under a BAA.
  • The voice agent runs on Retell AI under an executed BAA.
  • Retention and redaction settings for call recordings.In progress

Subprocessors

Vendors that process data on our behalf. A Business Associate Agreement is executed with every PHI-touching subprocessor before any live patient data is onboarded.

Vendor agreements. BAAs are executed progressively ahead of any PHI, not all at once. The status column below is the current position for each vendor, and executed agreements and their records are retained. Retell AI uses its own subprocessors for telephony, speech recognition, language models and speech synthesis; its current list is at trust.retellai.com/subprocessors.

Last updated September 2, 2026

VendorPurposeTouches PHIBAA status
Retell AIVoice infrastructureYesBAA executed (Jul 2026)
Google WorkspaceBusiness email and documentsYesBAA + CDPA executed (Jul 2026)
AWSFile storage, email transportYesBAA executed at account setup
Google CloudProduction application hosting and database (us-central1)YesBAA executed August 8, 2026
VercelMarketing site hostingNo, never in a PHI pathNot required; PHI-free by architecture
NeonDevelopment databaseNo, development data onlyNot required; PHI-free by architecture
StripeSubscription billing and paymentsNo, billing data onlyNot required; PHI-free by design
Cloudflare TurnstileBot protection on sign-in and sign-upNo, IP address and challenge token onlyNot required; never in a PHI path
ResendTransactional emailNo, PHI-free enforced by a fail-closed send-time scanNot required
PostHogProduct analyticsNo, no patient dataNot required

Documents

Public

Available on request

Each link opens an email to our team.

Frequently asked questions

Does Nem hold real patient data today?

Not yet. Production data is synthetic. Real patient data is accepted only after your BAA is signed and a tracked list of readiness items is closed; ask us for its current status.

Where is our data stored?

On Google Cloud in us-central1 (Iowa, USA), under a HIPAA Business Associate Agreement.

Do you sign a BAA?

Yes, at no extra charge, signed separately from the subscription and before any patient data is entered.

Is two-factor authentication required?

Not yet. Users can turn on authenticator-app two-factor authentication; requiring it on every account is still being switched on.

Can one clinic see another clinic's data?

Every database query is checked for a clinic boundary. Most core models already refuse an unscoped query; the remaining models, including patients, are being switched over in stages.

What happens if there is a security incident?

We notify affected clinics no later than five (5) business days after discovery. For patient data, the BAA sets this obligation.

Have you had a third-party audit, penetration test or SOC 2?

No. None has been completed. SOC 2 is planned, and we will not claim any of them before it is done.

Can we export our data if we leave?

Clinic-wide bulk export is in progress. Automatic deletion stays off until export is proven, so no clinic is told its data was recoverable when it was not.

Updates

  1. September 24, 2026

    Trust Center redesigned with a status for every compliance item and control, documents on request, and this log.

  2. September 2, 2026

    Subprocessor list reviewed end to end.

  3. August 13, 2026

    Production moved to Google Cloud (us-central1).

  4. August 8, 2026

    HIPAA Business Associate Agreement signed with Google Cloud.

  5. July 22, 2026

    Business Associate Agreement signed with Retell AI for the voice agent.

Honest framing. Nem is in beta. Every demo environment runs on synthetic data only; no real patient data is accepted until your BAA and our vendor BAAs are in place. HIPAA has no official certification, and no organization can be certified HIPAA compliant, so we do not claim one. What we can say is that our architecture is built to the HIPAA Security Rule safeguards, our self-attestation is in progress, and SOC 2 is planned rather than held. We will never claim a certification we do not have. The statements above describe our architecture and practices.