Security and trust
Exceptional security must be measurable.
NuaCares does not claim to be unhackable.
The current alpha remains blocked from public health-data use until independent security, privacy, accessibility, provider and operational evidence is complete.
Implemented locally
- Encrypted local vault using AES-GCM with a non-extractable in-memory key.
- Strict health-data schemas and deterministic evidence calculations.
- Purpose, scope, audience, person and expiry-bound consent contracts.
- Content-minimized audit, evidence, revocation and deletion receipts.
- Separate synthetic developer sandbox and fail-closed production feature flags.
- No raw health content in the public website, public analytics or public forms.
Required before the health app can launch
- Independent penetration test and closure of critical and high findings.
- Production identity, phishing-resistant authentication and recovery validation.
- Authoritative provider and device conformance testing.
- External privacy, clinical, regulatory and accessibility review.
- Named incident owners, on-call coverage, rollback and deletion drills.
AI boundary
The design does not give a language model database credentials, vault decryption authority or autonomous health-action authority. Numeric or comparative answers must resolve to evidence references or abstain.
Reporting a security concern
A public vulnerability-disclosure channel has not yet been activated. Do not send sensitive findings or health data through ordinary public channels. That channel is a launch prerequisite and will be published here when independently verified.