Trust Center
Before trusting a platform with your health data, you need to understand how it protects, audits and governs every decision. This page consolidates everything.
Security
Security architecture
Five control domains: identity, data, AI, governance and incident response.
See detailsCompliance
Frameworks and regulations
LGPD, ISO 27001, ISO 27701, NIST CSF, CIS Controls, HIPAA and GDPR.
See detailsTransparency
Sub-processors
All third parties that process client data, with purpose and contractual basis.
See detailsSecurity
Security as architecture, not as a badge.
higeia is built on five control domains applied from the first commit. Every design decision favors auditability over convenience.
Identity and access
- SSO via SAML 2.0 / OIDC (Enterprise and Private)
- MFA required on all plans
- Granular RBAC per unit and module
- Sessions with configurable expiry
Data at rest and in transit
- TLS 1.3 on all connections
- AES-256 at rest (AWS KMS)
- BYO-KMS available on Private
- Encrypted backups with 30-day retention
AI and language models
- Versioned and auditable prompts
- No use of client data to train models
- Processing in configurable regions
- Human review required for material decisions
Audit trail
- Append-only log with chained hash
- Structured export in minutes
- Record of all material user actions
- Minimum retention of five years
Incident response
- Documented response plan
- Client notification within 48 hours
- ANPD notification when applicable (LGPD art. 48)
- Public incident history
Secure development
- SAST and DAST in CI/CD
- Annual penetration tests by independent third party
- Automated dependency scanning
- Responsible disclosure policy (security.txt)
Compliance
Built for the most demanding standards in healthcare.
higeia was designed to operate in the most demanding regulatory environment of Brazilian healthcare, with controls mapped against major international frameworks.
LGPD
Law 13.709/2018 — Legal basis of everything we do
Art. 11 (sensitive data), Art. 46 (security), Art. 48 (incidents)
ISO 27001 / 27701
ISMS and privacy management
Control mapping in the Certifications & Frameworks module
ISO 27799
Information security in health
Specific controls for PHI (Protected Health Information)
NIST CSF 2.0
Cybersecurity framework
Functions: Identify, Protect, Detect, Respond, Recover
CIS Controls v8
Critical security controls
IG1, IG2, IG3 mapped by operation scale
HIPAA / GDPR
International operations
Support for clients with operations in the US or EU
* higeia is aligned with these frameworks — not certified. Formal certifications are on the roadmap.
Transparency
Sub-processors
Each sub-processor is evaluated for security practices, data location and regulatory compliance before contracting. Clients are notified 30 days in advance of any addition.
Last updated: April 2026
| Sub-processor | Purpose | Location | Contractual basis |
|---|---|---|---|
| AWS | Hosting infrastructure and database | sa-east-1 (São Paulo) | DPA with SCCs |
| Anthropic | LLM provider (Claude, all plans) | USA | DPA with SCCs |
| LLM provider (Gemini, all plans) | USA | DPA with SCCs | |
| Airtable | Lead persistence from contact form | USA | DPA with SCCs |
| Resend | Transactional email (confirmation and notification) | USA | DPA with SCCs |
| Cloudflare | CDN, DNS, DDoS protection and edge computing | Global (edge) | DPA with SCCs |
LGPD
Data subject rights
Regarding the data of higeia platform users (client collaborators), you can exercise the rights of arts. 17–22 of LGPD at any time.
Data Protection Officer (DPO): higeia@saude.dev