NeraviseBack to homepage

Privacy and security

Security and Data Protection

Patient data protection is fundamental to how Neravise is designed. Privacy, controlled access, clinical accountability and auditability shape the product architecture.

Readiness statement: This page describes design principles and repository-supported safeguards. It is not a certification or guarantee of legal compliance. Production configuration, contracts, policies and customer responsibilities must be assessed for each deployment.

Patient Data First

Sensitive patient and clinical information is treated as requiring heightened protection throughout referral, assessment, review and reporting workflows.

Authentication and Access

Email OTP authentication and role-based permissions are designed to restrict practitioner, QA and admin actions to authorised workspaces and responsibilities.

Organisation Isolation

Organisation-aware access rules are designed to separate each organisation’s configuration and clinical records according to the configured security model.

Auditability

Important authentication, clinical workflow, review, playback and export actions can be recorded as audit events without placing clinical narrative in the audit record.

Clinical Oversight

Clinicians retain responsibility for reviewing and approving clinical information. AI-assisted content, where authorised, remains a draft and cannot replace professional judgement.

Private Recordings

Recording workflows are designed around consent, private storage, referral-level access checks and short-lived playback links.

UK Data Protection

Neravise Ltd is registered with the Information Commissioner’s Office (ICO). Neravise is designed with UK data-protection obligations in mind. Registration does not mean that the ICO has approved, certified or endorsed the product.

US Healthcare and HIPAA

Neravise is being designed to support secure neurodevelopmental assessment workflows for US healthcare organisations, with HIPAA-aligned privacy and security principles incorporated into the platform architecture.

Software features alone do not establish a healthcare organisation’s compliance. Before real US Protected Health Information is processed, relevant Business Associate Agreements, eligible vendor services, security configuration, organisational policies, risk analysis, legal review and customer responsibilities must be verified.

AI and Patient Data

Clinical information must not be sent to an AI or transcription provider merely because an integration exists. Production use requires documented organisational approval, appropriate consent, controlled access, data-processing and contractual arrangements, retention settings, eligible service configuration and clinician oversight. Clinical AI and transcription should remain disabled until those prerequisites are evidenced.

Shared Responsibility

Neravise provides workflow and security controls, while each customer remains responsible for its users, policies, lawful processing, configuration, training and professional practice. See the Privacy Notice or contact info@neravise.com without including patient-identifiable information.