Pular para o conteúdo
Trust

Trust Center

Before trusting a platform with your health data, you need to understand how it protects, audits and governs every decision. This page consolidates everything.

Security

Security as architecture, not as a badge.

higeia is built on five control domains applied from the first commit. Every design decision favors auditability over convenience.

Identity and access

  • SSO via SAML 2.0 / OIDC (Enterprise and Private)
  • MFA required on all plans
  • Granular RBAC per unit and module
  • Sessions with configurable expiry

Data at rest and in transit

  • TLS 1.3 on all connections
  • AES-256 at rest (AWS KMS)
  • BYO-KMS available on Private
  • Encrypted backups with 30-day retention

AI and language models

  • Versioned and auditable prompts
  • No use of client data to train models
  • Processing in configurable regions
  • Human review required for material decisions

Audit trail

  • Append-only log with chained hash
  • Structured export in minutes
  • Record of all material user actions
  • Minimum retention of five years

Incident response

  • Documented response plan
  • Client notification within 48 hours
  • ANPD notification when applicable (LGPD art. 48)
  • Public incident history

Secure development

  • SAST and DAST in CI/CD
  • Annual penetration tests by independent third party
  • Automated dependency scanning
  • Responsible disclosure policy (security.txt)

Compliance

Built for the most demanding standards in healthcare.

higeia was designed to operate in the most demanding regulatory environment of Brazilian healthcare, with controls mapped against major international frameworks.

LGPD

Law 13.709/2018 — Legal basis of everything we do

Art. 11 (sensitive data), Art. 46 (security), Art. 48 (incidents)

ISO 27001 / 27701

ISMS and privacy management

Control mapping in the Certifications & Frameworks module

ISO 27799

Information security in health

Specific controls for PHI (Protected Health Information)

NIST CSF 2.0

Cybersecurity framework

Functions: Identify, Protect, Detect, Respond, Recover

CIS Controls v8

Critical security controls

IG1, IG2, IG3 mapped by operation scale

HIPAA / GDPR

International operations

Support for clients with operations in the US or EU

* higeia is aligned with these frameworks — not certified. Formal certifications are on the roadmap.

Transparency

Sub-processors

Each sub-processor is evaluated for security practices, data location and regulatory compliance before contracting. Clients are notified 30 days in advance of any addition.

Last updated: April 2026

Sub-processorPurposeLocationContractual basis
AWSHosting infrastructure and databasesa-east-1 (São Paulo)DPA with SCCs
AnthropicLLM provider (Claude, all plans)USADPA with SCCs
GoogleLLM provider (Gemini, all plans)USADPA with SCCs
AirtableLead persistence from contact formUSADPA with SCCs
ResendTransactional email (confirmation and notification)USADPA with SCCs
CloudflareCDN, DNS, DDoS protection and edge computingGlobal (edge)DPA with SCCs

LGPD

Data subject rights

Regarding the data of higeia platform users (client collaborators), you can exercise the rights of arts. 17–22 of LGPD at any time.

AccessCorrectionAnonymizationPortabilityDeletionOpposition

Data Protection Officer (DPO): higeia@saude.dev