Security & Cryptographic Statement
Zero-Trust Architectural Principles & Enterprise-Grade Data Protection Standard
NRNathanTechnologies, LLC
131 Continental Dr, Suite 305, Newark, DE 19713, New Castle County, USA
Delaware Entity File Number: 10692981
1. Data Encryption Standards
The Electronic Medical Platform (EMP) employs cryptographic envelope encryption to protect sensitive health records and Personally Identifiable Information (PII) at rest and in transit.
- Encryption in Transit: All HTTP traffic is strictly upgraded to HTTPS using TLS 1.3 protocol encryption, enforced via Strict Transport Security (HSTS) with a 2-year preload duration.
- Encryption at Rest: Database PII fields, clinical notes, prescriptions, and medical letters are protected using Fernet symmetric ciphers and AES-256 envelope keys tied to individual patient records.
2. Server Infrastructure & Protected Media Access
EMP operates behind hardened Nginx web servers configured to strict security benchmarks.
- Protected Media Handoffs: Attached clinical documents, test results, and practitioner signatures are never exposed via public static directories. File delivery is handled through internal Nginx
X-Accel-Redirectheader transfers following session authorization. - Content Security Policy (CSP): Rigid CSP directives prohibit external script injections, inline unsafe evals, and unauthorized font/style sources.
3. Emergency Session Controls & Incident Response
Practitioners are equipped with immediate session controls directly within their profile management portal:
- Logout From All Devices: Instantly invalidates all active database sessions across all browsers and devices without resetting account credentials.
- Account Lockout Protocol: Deactivates account access globally (
user.is_active = False) in case of credential compromise, requiring manual verification with NRNathanTechnologies support to reinstate access.