Security & Compliance

Built for healthcare. Audited for trust.

Rivon Health stores some of the most sensitive data healthcare orgs handle — credentials, licenses, PHI. Here’s exactly how we protect it, and the standards we hold ourselves to.

Compliance posture

HIPAA

Aligned

BAA available; controls mapped to Security, Privacy, and Breach Notification Rules.

SOC 2 Type II

In progress

Controls implemented; observation window planned for 2026.

ISO 27001

Cross-walked

Annex A controls mapped; certification under evaluation.

GDPR

Aligned

Data subject rights, DPA available on request.

What we do, in plain English

The short list — the same controls a SOC 2 auditor would look for.

Access Control

Role-based access control with five-tier role model

Five distinct roles. Every API call checks the caller's role against the permission required for that endpoint, server-side. No role can grant itself elevated access.

Access Control

Multi-tenant isolation enforced at the application and database layers

Your data is isolated from every other customer at two independent layers: the application middleware and PostgreSQL Row-Level Security.

Access Control

Single Sign-On (Google, Microsoft 365) and credential auth

Sign in with Google, Microsoft 365, or email + password. Passwords are bcrypt-hashed at cost 12 — never stored in plaintext.

Cryptography

Encryption at rest — sensitive fields with AES-256-GCM

SSN, EIN, DEA numbers, third-party credentials, and integration tokens are AES-256 encrypted at rest. The encryption key is never stored in the database.

Cryptography

Encryption at rest — full database

Every byte of the database — and every backup — is AES-256 encrypted at rest by Supabase.

Cryptography

Encryption in transit — TLS 1.2+ everywhere

Every connection — your browser to our app, our app to the database, our app to your webhook URL — is TLS 1.2 or higher. No plaintext on the wire.

Application Security

Rate limiting on all authentication endpoints

Brute-force and credential-stuffing protection: rate-limited login, registration, and verification — with explicit 429 responses and Retry-After headers.

Logging & Monitoring

Tamper-evident audit log on every mutation

Every change to your data is recorded in an append-only audit log: who did what, when, from which IP, with the before-and-after values.

All controls

37 controls grouped by domain. For an auditor-friendly export, contact security@rivon.health.

Access Control5 controls
  • Role-based access control with five-tier role model AC-01

    Every user has exactly one of five roles: Super Admin, Rivon Admin, Org Admin, Specialist, Provider. Each tRPC procedure declares the permission it requires; permissions are mapped to roles in src/lib/permissions.ts and enforced server-side on every request.

    SOC 2: Security, Confidentiality · HIPAA: §164.308(a)(4) — Information Access Management

  • Multi-tenant isolation enforced at the application and database layers AC-02

    Every tenant-scoped row carries org_id. The enforceTenant tRPC middleware injects orgId on every request from the session and rejects calls without one. PostgreSQL Row-Level Security is enabled on every public table as a second wall — even a leaked anon key returns zero rows.

    SOC 2: Security, Confidentiality · HIPAA: §164.308(a)(4)(ii)(B) — Access Authorization

  • Single Sign-On (Google, Microsoft 365) and credential auth AC-03

    NextAuth.js handles authentication. Email+password uses bcryptjs (cost factor 12). Google and Microsoft Azure AD providers are first-class. Passwords never leave the server unhashed.

    SOC 2: Security · HIPAA: §164.308(a)(5)(ii)(D) — Password Management

  • Session management with secure JWTs AC-04

    Sessions are JWT-backed by NextAuth, signed with NEXTAUTH_SECRET. Cookies are httpOnly, secure, sameSite=lax. Sessions expire on inactivity per the NextAuth defaults.

    SOC 2: Security · HIPAA: §164.312(a)(2)(iii) — Automatic Logoff

  • Per-user permission overrides with audit trail AC-05

    Org admins can grant or revoke individual permissions on a member without changing their role. Every override is stored in user_permission_overrides and surfaced in /settings/team. The effective permission set is computed on every request.

    SOC 2: Security · HIPAA: §164.308(a)(4)(ii)(C) — Access Establishment and Modification

Cryptography5 controls
  • Encryption at rest — sensitive fields with AES-256-GCM CR-01

    PHI-adjacent fields (SSN/EIN, DEA numbers, third-party login passwords/PINs, OAuth refresh tokens for Asana) are AES-256-GCM encrypted via src/lib/encryption.ts using a 32-byte master key (ENCRYPTION_MASTER_KEY env var). The key never appears in code.

    SOC 2: Security, Confidentiality · HIPAA: §164.312(a)(2)(iv) — Encryption and Decryption

  • Encryption at rest — full database CR-02

    Supabase Postgres uses AES-256 disk encryption by default on all production projects. Backups are also encrypted at rest in S3.

    SOC 2: Security, Confidentiality · HIPAA: §164.312(a)(2)(iv)

  • Encryption in transit — TLS 1.2+ everywhere CR-03

    All client traffic to app.rivon.health is served over HTTPS via Vercel's edge with TLS 1.2 minimum. Server-to-database connections use TLS to Supabase. Server-to-Supabase Storage uses TLS. Outbound webhooks require HTTPS endpoints.

    SOC 2: Security, Confidentiality · HIPAA: §164.312(e)(1) — Transmission Security

  • API key hashing CR-04

    Public API keys are stored as SHA-256 hashes; the raw key is shown to the user exactly once at mint time. Even a database leak does not expose usable keys.

    SOC 2: Security · HIPAA: §164.312(d) — Person or Entity Authentication

  • Webhook signature verification (HMAC-SHA256) CR-05

    Outbound webhooks are signed with HMAC-SHA256 using a per-endpoint secret. Partners verify the X-Rivon-Signature header to confirm payload authenticity and integrity.

    SOC 2: Security, Processing Integrity

Application Security5 controls
  • Rate limiting on all authentication endpoints AS-01

    Sign-in: 5 attempts/min per (IP, email) and 50/day per IP. Register: 5/10min and 20/24h per IP. Signup-with-plan: 3/10min and 10/24h per IP. Verify-email: 30/min per IP. Buckets enforced in src/lib/rate-limit.ts; 429 returned with Retry-After.

    SOC 2: Security · HIPAA: §164.308(a)(5)(ii)(C) — Login Monitoring

  • CAPTCHA on free-tier signup (Cloudflare Turnstile) AS-02

    Free-tier signup form requires a Cloudflare Turnstile challenge. Token is verified server-side against Cloudflare before the user row is written. Blocks automated mass account creation.

    SOC 2: Security

  • Email verification on free-tier signup AS-03

    Free signups receive a one-shot verification token (32-byte random, 24h TTL) via Resend. Account remains in unverified state until they click the link. Lives in the existing VerificationToken table.

    SOC 2: Security

  • Input validation with Zod on every mutation AS-04

    Every tRPC mutation declares a Zod schema for its input. Requests that fail validation never reach the business-logic layer. Prevents whole classes of injection and over-posting.

    SOC 2: Security, Processing Integrity

  • Secure HTTP headers (Vercel default + Next.js framework) AS-05

    Vercel automatically sends Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options=DENY, and Referrer-Policy. Next.js adds CSP-friendly defaults.

    SOC 2: Security

Data Protection3 controls
  • Soft-delete with retention on every table DP-01

    Every business table has a deleted_at timestamp. Deletes set the timestamp instead of removing the row, enabling 30-day undelete on customer request and preserving the audit trail.

    SOC 2: Security, Processing Integrity · HIPAA: §164.310(d)(2)(iv) — Data Backup and Storage

  • PHI scope gating on the public REST API DP-02

    The public API requires a phi:read scope before exposing DOB, SSN/EIN, full address, or birthplace. Keys without phi:read see masked or omitted fields. phi:read scope is only granted by Rivon staff after a signed BAA.

    SOC 2: Security, Confidentiality, Privacy · HIPAA: §164.502(b) — Minimum Necessary

  • Org suspension and deletion DP-03

    Super admins can suspend an org (members blocked from all tRPC calls with a friendly reason) or soft-delete (full denial). Both are reversible. Enforced in the enforceTenant middleware on every request.

    SOC 2: Security

Vulnerability Management3 controls
  • Continuous database advisor scanning (Supabase) VM-01

    Supabase's security advisor runs automatically on every project change. Scans for missing RLS, exposed sensitive columns, weak privileges. Findings reviewed and resolved by Rivon staff. Currently zero ERROR or WARN findings.

    SOC 2: Security

  • Dependency monitoring VM-02

    GitHub Dependabot is enabled on the rivon-health-crm repository. Critical and high CVE alerts route to the engineering Slack channel. npm audit run as part of CI on every push.

    SOC 2: Security

  • Annual penetration test VM-03

    Engage a third-party offensive security firm to perform a black/grey-box pentest annually before SOC 2 Type II certification. Findings remediated against tracked timelines.

    SOC 2: Security

Logging & Monitoring3 controls
  • Tamper-evident audit log on every mutation LM-01

    Every data mutation writes to the audit_log table with actor user, action, entity type, entity id, before/after diff, IP, and timestamp. Append-only by design. Includes cross-org actions like apiKey.createForOrg, recorded in the target org's log.

    SOC 2: Security, Processing Integrity · HIPAA: §164.312(b) — Audit Controls

  • Application logs centralized in Vercel LM-02

    Every serverless function call emits structured logs to Vercel's logging service. 7-day retention on Hobby, 30-day on Pro. Searchable by request ID, status, level.

    SOC 2: Security

  • Database query logs LM-03

    Supabase logs all Postgres queries, errors, and connection events. Queryable via Supabase Studio for last 7 days.

    SOC 2: Security

Change Management3 controls
  • Code review and CI on every change CM-01

    Every code change goes through GitHub. Vercel runs production builds on every push to main; the build step runs `npm run build` which executes `prisma generate && next build` and fails on TypeScript errors. Failed builds do not deploy.

    SOC 2: Security, Processing Integrity

  • Database migrations via versioned SQL files CM-02

    Schema changes go through Supabase's apply_migration with a snake_case name. Every applied migration is recorded in the supabase_migrations.schema_migrations table with name, hash, and timestamp.

    SOC 2: Processing Integrity

  • Instant rollback via Vercel CM-03

    Every deployment is immutable and addressable by URL. Promoting a previous deployment to production is a single click in the Vercel dashboard.

    SOC 2: Availability

Vendor Management1 control
  • Subprocessor inventory VD-01

    Maintained list of subprocessors that touch customer data: Vercel (hosting), Supabase (database, storage, auth), Resend (transactional email), Anthropic (AI). All have signed BAAs or DPAs as appropriate.

    SOC 2: Confidentiality, Privacy · HIPAA: §164.308(b) — Business Associate Contracts

Business Continuity3 controls
  • Automated daily database backups BC-01

    Supabase performs daily automated backups with 7-day retention on the current plan. Point-in-time recovery available on Pro plan and above.

    SOC 2: Availability · HIPAA: §164.308(a)(7)(ii)(A) — Data Backup Plan

  • Multi-region edge delivery (Vercel) BC-02

    Static assets and serverless functions are delivered from Vercel's global edge network. Single-region database (us-west-2) keeps latency consistent for the primary user base.

    SOC 2: Availability

  • Documented disaster recovery runbook BC-03

    Step-by-step DR procedures for: Supabase project compromise, Vercel project compromise, encryption key rotation, mass-account compromise. RTO target: 4h. RPO target: 24h.

    SOC 2: Availability · HIPAA: §164.308(a)(7)(i)

Incident Response1 control
  • Incident response plan with severity tiers IR-01

    Documented incident process: detect → triage (P0–P3) → contain → eradicate → recover → postmortem. Customer notification SLA: 72h for confirmed PHI exposure (HIPAA Breach Notification Rule).

    SOC 2: Security · HIPAA: §164.308(a)(6) — Security Incident Procedures

HR & Training2 controls
  • Background checks on all Rivon staff HR-01

    All employees with production data access undergo background checks before access is provisioned.

    SOC 2: Security · HIPAA: §164.308(a)(3)(ii)(B) — Workforce Clearance Procedure

  • Annual security awareness + HIPAA training HR-02

    Mandatory annual training on security best practices, phishing awareness, HIPAA Privacy and Security Rules. Completion tracked.

    SOC 2: Security · HIPAA: §164.308(a)(5)(i) — Security Awareness and Training

Physical Security1 control
  • All infrastructure hosted in SOC 2 Type II + HIPAA-compliant data centers PS-01

    Vercel runs on AWS (us-east-1, us-west-1, etc.), Supabase on AWS (us-west-2). Both cloud providers' physical security is independently audited (AWS SOC 1/2/3, ISO 27001, HIPAA).

    SOC 2: Security, Availability · HIPAA: §164.310 — Physical Safeguards

Privacy2 controls
  • BAA available for every customer handling PHI PR-01

    Standard Business Associate Agreement template available at /security/baa. Required signature before any PHI is uploaded. Enforced via the phi:read API scope.

    SOC 2: Privacy, Confidentiality · HIPAA: §164.504(e) — BAA Required Provisions

  • Data subject rights (access, amendment, accounting of disclosures) PR-02

    Provider portal lets providers see all data Rivon stores about them. Org admins can amend any field. Audit log provides accounting of disclosures going back to the org's start date.

    SOC 2: Privacy · HIPAA: §164.524, §164.526, §164.528

Report a security issue

Found a vulnerability? Email security@rivon.health. We acknowledge within one business day and will not pursue legal action against good-faith research.