Trust & security

Boring where it matters.

Compliance, security and audit are the parts of NefraOne you should never have to think about - so we think about them constantly. Here is exactly how patient records, billing and registry data are protected.

eNRR / MDTR-ready

Registry fields captured at the bedside, prepped for every annual return.

LHDN e-Invoice

Validated e-Invoices straight from sessions - patients and sponsors alike.

Full audit log

Every change, every actor, every timestamp. Nothing happens off the record.

Role-based access

Nurses see their patients. Managers see their branch. Owners see everything.

ISO/IEC 27001

Information-security management built to the standard - certification underway.

iPad-first floor UI

Big touch targets, guided steps, camera scanning. Designed for gloved hands.

The practices

How we protect the record.

Encrypted everywhere

TLS in transit, encryption at rest - patient records never travel or sleep in the clear.

Least-privilege access

Every role sees exactly what its job needs - nothing more. Access is granted, scoped and revocable.

Immutable audit trail

Creates, edits, imports, sign-ins - every action is recorded with actor, timestamp and context.

Continuous backups

Point-in-time recovery on managed infrastructure - a bad day never becomes a lost record.

Privacy by default

PDPA-minded handling of ICs and clinical data - collected for care, shown only where care needs it.

Managed, monitored infrastructure

Hosted on hardened cloud infrastructure with health monitoring and controlled deployments.

ISO/IEC 27001 - certification underway

NefraOne's information-security management system is built to the ISO/IEC 27001 standard, and we are working through independent certification to prove it. Security at the highest level - verified by auditors, not just promised by us.

ISMS policies in place Controls mapped to Annex A independent audit in progress

Questions from your security team?

Send them over - we answer security questionnaires directly, and quickly.