Security & privacy

Built for BC PIPA
from day one.

How Nidl handles PHI, where it lives, who can see it, and the line we draw between AI assistance and clinical decisions. Last reviewed Jul 2026.

Data residency
Canada-only
AWS / Azure ca-central-1 + ca-west-1. Never crosses the border.
Encryption
AES-256 + TLS 1.2+
Per-tenant KMS envelope encryption at rest.
Audit trail
Hash-chained
Append-only, tamper-evident, 7-year retention.
Compliance
PIPA-first
BC PIPA today · PHIPA-ready · PIPEDA-aligned.
Data residency

PHI stays in Canada.
Period.

Production data — including patient identifiers, documents, audit logs, and message contents — is stored exclusively in Canadian cloud regions. Cross-border transit is prohibited by tenant policy and enforced at the network layer.

Primary: AWS Canada Central (Montréal)
DR: Azure Canada West (Vancouver)
No US-East fallback, ever
EU sub-processors only for non-PHI metadata
Map of Canada marking Nidl's Canadian cloud regions: Montréal, Vancouver, and Toronto.
Vancouver · DR
Montréal · Primary
Toronto · SMS
[ schematic · cloud regions where PHI may reside ]
Controls

Three boundaries
that don’t move.

Access

Least-privilege by role.

Front desk, reviewer, provider, and admin roles ship with site-scoped permissions. Workspace owners can customize the matrix. SSO via SAML 2.0; 2FA optional but recommended.

  • Role-based access control (RBAC) with audit on every grant change
  • Optional SSO with Health Authority IdPs
  • Session expiry, IP allowlist, device approvals
Audit

Every read, write, export.

Each event is recorded with actor, entity, trace ID, and a cryptographic hash that chains to the prior. Daily bundles are exported to compliance contacts automatically.

  • Append-only event ledger · daily verification
  • Pre-built audit exports for BC PIPA / PHIPA review
  • Replayable trace IDs for any clinical or admin action
Operational only

We do not make clinical decisions.

Nidl handles operations — routing, classification, status messages. No diagnosis, no prescribing, no clinical recommendation surfaces in the patient record without a human action.

  • Low-confidence items always require staff confirmation
  • Suggested next steps are reviewable artifacts, never autonomous
  • Pre-defined escalation paths for ambiguous or urgent items
Sub-processors

Everyone we share with.

A full list of vendors that touch any part of the pipeline. Updated whenever it changes; you’ll see this list in your data processing agreement.

VendorPurposeRegion / notes
AWS Canada Central (ca-central-1)Primary infrastructure · PHI storageMontréal, QC
Azure Canada WestDR / cross-region replicasVancouver, BC
Twilio CanadaSMS delivery for patient statusca-toronto-1
SendGrid (Mailgun EU fallback)Transactional emailRouting kept in Canada via tenant policy
Azure OpenAI Service · Canada CentralAI classification + drafting (opt-in, pilot)Toronto · model inference stays in Canada · zero data retention · no PHI used for training
Google Analytics 4Marketing site analytics (page views, traffic sources)USA (Google Cloud) · no PHI · marketing pages only · workspace + patient-hub routes excluded by pathname allowlist
Incident response

What happens
if something breaks.

DetectionContinuous monitoring + uptime probes from 3 regions. Page-on-call within 60 seconds of anomaly.
ContainmentPer-tenant kill switch on every external integration. Confirmed in <5 minutes.
NotificationBC-eligible breaches notified to designated clinic contact + the BC OIPC within 72 hours.
Post-mortemPublic, blameless write-up within 7 days of resolution. Past reports are linked in your DPA.
Questions?

Talk to our privacy officer.

Compliance review, DPA requests, sub-processor changes, and disclosure inquiries.