NOW AVAILABLEClinical Intelligence Platform — Now Available

Legal

Data Security

How Nyelux protects the product content, training and conversations you trust it with: where the platform runs, how data is encrypted, who can reach it, and what happens if something goes wrong.

Platform and encryption

Where it runs

  • The Nyelux API, databases and uploaded files run on Amazon Web Services in the US East region
  • The web application is served by Vercel
  • AI answers are generated with Microsoft Azure OpenAI Service
  • No Nyelux systems run in an office or on company premises

Encryption

  • Connections to nyelux.com and the Nyelux API use TLS 1.2 or higher, with HSTS; TLS 1.0 and 1.1 are refused
  • Uploaded files are encrypted at rest in Amazon S3
  • Two-factor secrets and connected-app tokens are encrypted by the application before they are stored
  • Passwords are stored only as bcrypt hashes

Access control

Sign-in

  • Individual accounts for every user
  • Five failed password attempts in a row lock an account for 30 minutes
  • Sign-in attempts are rate limited
  • While Nyelux is open in your browser, it signs you out after 30 minutes of inactivity

Permissions

  • Separate roles for organization administrators, representatives and clinicians
  • The server, not the browser, decides what each user can see, based on their organization and role

Records

  • Changes to who can see a document are recorded in an audit log, and so are document opens by clinicians
  • Key administrative actions by Nyelux staff, such as approving organizations and creating administrator accounts, are recorded
  • Each successful Epic launch is recorded

Engineering and incident response

How web app changes ship

  • Changes to the Nyelux web app are made through pull requests
  • Automated dependency and secret scans run on each of those pull requests

If something goes wrong

  • A written incident response procedure, led by our Information Security Officer
  • Affected customers are told without undue delay, and no later than 72 hours after we confirm an incident that affects their data

Patient information

Nyelux is designed so that no one needs to enter patient health information to use it. Please do not enter patient names, record numbers, dates of birth or other identifiers. See HIPAA and patient data for how we handle it if it is entered anyway.


Service providers that process customer data

  • Amazon Web Services: hosting, databases and file storage (US East)
  • Vercel: web application hosting
  • Microsoft Azure OpenAI Service: AI answers and document processing
  • Elastic Cloud: device search
  • SendGrid (Twilio): transactional email
  • Twilio: SMS security alerts
  • Google and Microsoft: sign-in, calendar sync, document previews, and imports you choose to connect
  • Cloudflare: bot checks for the assistant on manufacturers’ websites

Compliance status and security reviews

Nyelux is preparing for a SOC 2 Type 2 examination. No SOC 2 report has been issued yet; we will say so here when one has.

We answer security questionnaires and support vendor risk reviews. To report a security issue, email security@nyelux.com.