Security & Compliance
Built for healthcare. Audited for trust.
Rivon Health stores some of the most sensitive data healthcare orgs handle — credentials, licenses, PHI. Here’s exactly how we protect it, and the standards we hold ourselves to.
Compliance posture
What we do, in plain English
The short list — the same controls a SOC 2 auditor would look for.
Access Control
Role-based access control with five-tier role model
Five distinct roles. Every API call checks the caller's role against the permission required for that endpoint, server-side. No role can grant itself elevated access.
Access Control
Multi-tenant isolation enforced at the application and database layers
Your data is isolated from every other customer at two independent layers: the application middleware and PostgreSQL Row-Level Security.
Access Control
Single Sign-On (Google, Microsoft 365) and credential auth
Sign in with Google, Microsoft 365, or email + password. Passwords are bcrypt-hashed at cost 12 — never stored in plaintext.
Cryptography
Encryption at rest — sensitive fields with AES-256-GCM
SSN, EIN, DEA numbers, third-party credentials, and integration tokens are AES-256 encrypted at rest. The encryption key is never stored in the database.
Cryptography
Encryption at rest — full database
Every byte of the database — and every backup — is AES-256 encrypted at rest by Supabase.
Cryptography
Encryption in transit — TLS 1.2+ everywhere
Every connection — your browser to our app, our app to the database, our app to your webhook URL — is TLS 1.2 or higher. No plaintext on the wire.
Application Security
Rate limiting on all authentication endpoints
Brute-force and credential-stuffing protection: rate-limited login, registration, and verification — with explicit 429 responses and Retry-After headers.
Logging & Monitoring
Tamper-evident audit log on every mutation
Every change to your data is recorded in an append-only audit log: who did what, when, from which IP, with the before-and-after values.
All controls
37 controls grouped by domain. For an auditor-friendly export, contact security@rivon.health.
Access Control5 controls
Role-based access control with five-tier role model AC-01
Every user has exactly one of five roles: Super Admin, Rivon Admin, Org Admin, Specialist, Provider. Each tRPC procedure declares the permission it requires; permissions are mapped to roles in src/lib/permissions.ts and enforced server-side on every request.
SOC 2: Security, Confidentiality · HIPAA: §164.308(a)(4) — Information Access Management
Multi-tenant isolation enforced at the application and database layers AC-02
Every tenant-scoped row carries org_id. The enforceTenant tRPC middleware injects orgId on every request from the session and rejects calls without one. PostgreSQL Row-Level Security is enabled on every public table as a second wall — even a leaked anon key returns zero rows.
SOC 2: Security, Confidentiality · HIPAA: §164.308(a)(4)(ii)(B) — Access Authorization
Single Sign-On (Google, Microsoft 365) and credential auth AC-03
NextAuth.js handles authentication. Email+password uses bcryptjs (cost factor 12). Google and Microsoft Azure AD providers are first-class. Passwords never leave the server unhashed.
SOC 2: Security · HIPAA: §164.308(a)(5)(ii)(D) — Password Management
Session management with secure JWTs AC-04
Sessions are JWT-backed by NextAuth, signed with NEXTAUTH_SECRET. Cookies are httpOnly, secure, sameSite=lax. Sessions expire on inactivity per the NextAuth defaults.
SOC 2: Security · HIPAA: §164.312(a)(2)(iii) — Automatic Logoff
Per-user permission overrides with audit trail AC-05
Org admins can grant or revoke individual permissions on a member without changing their role. Every override is stored in user_permission_overrides and surfaced in /settings/team. The effective permission set is computed on every request.
SOC 2: Security · HIPAA: §164.308(a)(4)(ii)(C) — Access Establishment and Modification
Cryptography5 controls
Encryption at rest — sensitive fields with AES-256-GCM CR-01
PHI-adjacent fields (SSN/EIN, DEA numbers, third-party login passwords/PINs, OAuth refresh tokens for Asana) are AES-256-GCM encrypted via src/lib/encryption.ts using a 32-byte master key (ENCRYPTION_MASTER_KEY env var). The key never appears in code.
SOC 2: Security, Confidentiality · HIPAA: §164.312(a)(2)(iv) — Encryption and Decryption
Encryption at rest — full database CR-02
Supabase Postgres uses AES-256 disk encryption by default on all production projects. Backups are also encrypted at rest in S3.
SOC 2: Security, Confidentiality · HIPAA: §164.312(a)(2)(iv)
Encryption in transit — TLS 1.2+ everywhere CR-03
All client traffic to app.rivon.health is served over HTTPS via Vercel's edge with TLS 1.2 minimum. Server-to-database connections use TLS to Supabase. Server-to-Supabase Storage uses TLS. Outbound webhooks require HTTPS endpoints.
SOC 2: Security, Confidentiality · HIPAA: §164.312(e)(1) — Transmission Security
API key hashing CR-04
Public API keys are stored as SHA-256 hashes; the raw key is shown to the user exactly once at mint time. Even a database leak does not expose usable keys.
SOC 2: Security · HIPAA: §164.312(d) — Person or Entity Authentication
Webhook signature verification (HMAC-SHA256) CR-05
Outbound webhooks are signed with HMAC-SHA256 using a per-endpoint secret. Partners verify the X-Rivon-Signature header to confirm payload authenticity and integrity.
SOC 2: Security, Processing Integrity
Application Security5 controls
Rate limiting on all authentication endpoints AS-01
Sign-in: 5 attempts/min per (IP, email) and 50/day per IP. Register: 5/10min and 20/24h per IP. Signup-with-plan: 3/10min and 10/24h per IP. Verify-email: 30/min per IP. Buckets enforced in src/lib/rate-limit.ts; 429 returned with Retry-After.
SOC 2: Security · HIPAA: §164.308(a)(5)(ii)(C) — Login Monitoring
CAPTCHA on free-tier signup (Cloudflare Turnstile) AS-02
Free-tier signup form requires a Cloudflare Turnstile challenge. Token is verified server-side against Cloudflare before the user row is written. Blocks automated mass account creation.
SOC 2: Security
Email verification on free-tier signup AS-03
Free signups receive a one-shot verification token (32-byte random, 24h TTL) via Resend. Account remains in unverified state until they click the link. Lives in the existing VerificationToken table.
SOC 2: Security
Input validation with Zod on every mutation AS-04
Every tRPC mutation declares a Zod schema for its input. Requests that fail validation never reach the business-logic layer. Prevents whole classes of injection and over-posting.
SOC 2: Security, Processing Integrity
Secure HTTP headers (Vercel default + Next.js framework) AS-05
Vercel automatically sends Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options=DENY, and Referrer-Policy. Next.js adds CSP-friendly defaults.
SOC 2: Security
Data Protection3 controls
Soft-delete with retention on every table DP-01
Every business table has a deleted_at timestamp. Deletes set the timestamp instead of removing the row, enabling 30-day undelete on customer request and preserving the audit trail.
SOC 2: Security, Processing Integrity · HIPAA: §164.310(d)(2)(iv) — Data Backup and Storage
PHI scope gating on the public REST API DP-02
The public API requires a phi:read scope before exposing DOB, SSN/EIN, full address, or birthplace. Keys without phi:read see masked or omitted fields. phi:read scope is only granted by Rivon staff after a signed BAA.
SOC 2: Security, Confidentiality, Privacy · HIPAA: §164.502(b) — Minimum Necessary
Org suspension and deletion DP-03
Super admins can suspend an org (members blocked from all tRPC calls with a friendly reason) or soft-delete (full denial). Both are reversible. Enforced in the enforceTenant middleware on every request.
SOC 2: Security
Vulnerability Management3 controls
Continuous database advisor scanning (Supabase) VM-01
Supabase's security advisor runs automatically on every project change. Scans for missing RLS, exposed sensitive columns, weak privileges. Findings reviewed and resolved by Rivon staff. Currently zero ERROR or WARN findings.
SOC 2: Security
Dependency monitoring VM-02
GitHub Dependabot is enabled on the rivon-health-crm repository. Critical and high CVE alerts route to the engineering Slack channel. npm audit run as part of CI on every push.
SOC 2: Security
Annual penetration test VM-03
Engage a third-party offensive security firm to perform a black/grey-box pentest annually before SOC 2 Type II certification. Findings remediated against tracked timelines.
SOC 2: Security
Logging & Monitoring3 controls
Tamper-evident audit log on every mutation LM-01
Every data mutation writes to the audit_log table with actor user, action, entity type, entity id, before/after diff, IP, and timestamp. Append-only by design. Includes cross-org actions like apiKey.createForOrg, recorded in the target org's log.
SOC 2: Security, Processing Integrity · HIPAA: §164.312(b) — Audit Controls
Application logs centralized in Vercel LM-02
Every serverless function call emits structured logs to Vercel's logging service. 7-day retention on Hobby, 30-day on Pro. Searchable by request ID, status, level.
SOC 2: Security
Database query logs LM-03
Supabase logs all Postgres queries, errors, and connection events. Queryable via Supabase Studio for last 7 days.
SOC 2: Security
Change Management3 controls
Code review and CI on every change CM-01
Every code change goes through GitHub. Vercel runs production builds on every push to main; the build step runs `npm run build` which executes `prisma generate && next build` and fails on TypeScript errors. Failed builds do not deploy.
SOC 2: Security, Processing Integrity
Database migrations via versioned SQL files CM-02
Schema changes go through Supabase's apply_migration with a snake_case name. Every applied migration is recorded in the supabase_migrations.schema_migrations table with name, hash, and timestamp.
SOC 2: Processing Integrity
Instant rollback via Vercel CM-03
Every deployment is immutable and addressable by URL. Promoting a previous deployment to production is a single click in the Vercel dashboard.
SOC 2: Availability
Vendor Management1 control
Subprocessor inventory VD-01
Maintained list of subprocessors that touch customer data: Vercel (hosting), Supabase (database, storage, auth), Resend (transactional email), Anthropic (AI). All have signed BAAs or DPAs as appropriate.
SOC 2: Confidentiality, Privacy · HIPAA: §164.308(b) — Business Associate Contracts
Business Continuity3 controls
Automated daily database backups BC-01
Supabase performs daily automated backups with 7-day retention on the current plan. Point-in-time recovery available on Pro plan and above.
SOC 2: Availability · HIPAA: §164.308(a)(7)(ii)(A) — Data Backup Plan
Multi-region edge delivery (Vercel) BC-02
Static assets and serverless functions are delivered from Vercel's global edge network. Single-region database (us-west-2) keeps latency consistent for the primary user base.
SOC 2: Availability
Documented disaster recovery runbook BC-03
Step-by-step DR procedures for: Supabase project compromise, Vercel project compromise, encryption key rotation, mass-account compromise. RTO target: 4h. RPO target: 24h.
SOC 2: Availability · HIPAA: §164.308(a)(7)(i)
Incident Response1 control
Incident response plan with severity tiers IR-01
Documented incident process: detect → triage (P0–P3) → contain → eradicate → recover → postmortem. Customer notification SLA: 72h for confirmed PHI exposure (HIPAA Breach Notification Rule).
SOC 2: Security · HIPAA: §164.308(a)(6) — Security Incident Procedures
HR & Training2 controls
Background checks on all Rivon staff HR-01
All employees with production data access undergo background checks before access is provisioned.
SOC 2: Security · HIPAA: §164.308(a)(3)(ii)(B) — Workforce Clearance Procedure
Annual security awareness + HIPAA training HR-02
Mandatory annual training on security best practices, phishing awareness, HIPAA Privacy and Security Rules. Completion tracked.
SOC 2: Security · HIPAA: §164.308(a)(5)(i) — Security Awareness and Training
Physical Security1 control
All infrastructure hosted in SOC 2 Type II + HIPAA-compliant data centers PS-01
Vercel runs on AWS (us-east-1, us-west-1, etc.), Supabase on AWS (us-west-2). Both cloud providers' physical security is independently audited (AWS SOC 1/2/3, ISO 27001, HIPAA).
SOC 2: Security, Availability · HIPAA: §164.310 — Physical Safeguards
Privacy2 controls
BAA available for every customer handling PHI PR-01
Standard Business Associate Agreement template available at /security/baa. Required signature before any PHI is uploaded. Enforced via the phi:read API scope.
SOC 2: Privacy, Confidentiality · HIPAA: §164.504(e) — BAA Required Provisions
Data subject rights (access, amendment, accounting of disclosures) PR-02
Provider portal lets providers see all data Rivon stores about them. Org admins can amend any field. Audit log provides accounting of disclosures going back to the org's start date.
SOC 2: Privacy · HIPAA: §164.524, §164.526, §164.528
Report a security issue
Found a vulnerability? Email security@rivon.health. We acknowledge within one business day and will not pursue legal action against good-faith research.