Security & Cryptographic Statement

Zero-Trust Architectural Principles & Enterprise-Grade Data Protection Standard

NRNathanTechnologies, LLC 131 Continental Dr, Suite 305, Newark, DE 19713, New Castle County, USA Delaware Entity File Number: 10692981

1. Data Encryption Standards

The Electronic Medical Platform (EMP) employs cryptographic envelope encryption to protect sensitive health records and Personally Identifiable Information (PII) at rest and in transit.

  • Encryption in Transit: All HTTP traffic is strictly upgraded to HTTPS using TLS 1.3 protocol encryption, enforced via Strict Transport Security (HSTS) with a 2-year preload duration.
  • Encryption at Rest: Database PII fields, clinical notes, prescriptions, and medical letters are protected using Fernet symmetric ciphers and AES-256 envelope keys tied to individual patient records.

2. Server Infrastructure & Protected Media Access

EMP operates behind hardened Nginx web servers configured to strict security benchmarks.

  • Protected Media Handoffs: Attached clinical documents, test results, and practitioner signatures are never exposed via public static directories. File delivery is handled through internal Nginx X-Accel-Redirect header transfers following session authorization.
  • Content Security Policy (CSP): Rigid CSP directives prohibit external script injections, inline unsafe evals, and unauthorized font/style sources.

3. Emergency Session Controls & Incident Response

Practitioners are equipped with immediate session controls directly within their profile management portal:

  • Logout From All Devices: Instantly invalidates all active database sessions across all browsers and devices without resetting account credentials.
  • Account Lockout Protocol: Deactivates account access globally (user.is_active = False) in case of credential compromise, requiring manual verification with NRNathanTechnologies support to reinstate access.