Security
Last updated 13 July 2026
Medical records deserve careful handling. Here is how Ouvela protects them, in plain language.
Encryption
Records are encrypted in transit and at rest. The original documents you upload are stored in encrypted object storage, with keys managed by a dedicated key service.
Isolation between accounts
Every record belongs to one account, and the database enforces that boundary with row-level security. Each account’s records are kept isolated from other accounts’ by design. This isolation is enforced at the data layer, not just in application code.
Access and auditing
Within your account, only the people you invite can see the records allowed by their roles, and you can remove their access. Privileged access is intended to be least-privilege and logged; audit coverage across application, infrastructure, and support paths is validated separately.
Vetted providers
We use a small set of infrastructure and processing providers, under agreements that require them to protect health information and to use it only to deliver the service. We do not use your records to train AI, and we do not sell them.
Storage and processing location
Records are stored encrypted on Amazon Web Services in a fixed region. When a record is read, processing runs only through covered providers under signed Business Associate Agreements, with zero-retention controls where applicable. Processing geography can differ from storage geography.
Responsible disclosure
If you believe you have found a security issue, please email security@ouvela.com before disclosing it publicly. We welcome reports and will work with you in good faith. Machine-readable details are at /.well-known/security.txt.