Health data you can trust.

Keep direct identifiers out.

PAPatient privacy settingsPatient profile
Optional anonymisation
Use an anonymised profile
NameAlex MorganEmaila•••••@mail.comDate of birth12 Mar 1978StatusIdentified

Choose whether the source file remains.

ERSource-file retention
Optional deletion
PDFlaboratory-results-14-mar-2025.pdfEncrypted during processingProcessing
✓ Health data organised · selected source-file setting applied

Encrypted in transit and at rest.

SECEncryptionRecords and uploaded files
TLS · AES-256
In transit
TLS
At rest
AES-256
Records and uploads✓ Protected

Access follows the user’s role.

IDWorkspace accessIdentity and permissions
Authenticated
Account verified✓Role checked✓Permission granted✓

Important activity leaves a trail.

ALAudit trailSecurity activity
Recorded
Account sign-in✓Report access✓Session revoked✓

Share only when it is ready.

HSReport accessHealth Summary
Clinician controlled
Approved reportHealth Summary
Clinician approval complete✓
Patient access enabled✓
Security foundations

Built around recognized safeguards.

Encryption

Your records stay protected

Encrypted during transfer and storage, with short-lived document links.

Infrastructure

Built on trusted hosting

Hosted on infrastructure certified to SOC 2 Type II.

Privacy rights

Your data is not the product

No sale of patient data or use for targeted advertising. Read more →

Healthcare workflows

Ready for HIPAA workflows

Appropriate safeguards and Business Associate Agreements where HIPAA applies.

Providers & BAAs

Protection extends to the providers we use.

Providers receive only the information needed to deliver their service. When a provider handles protected health information on our behalf, n1 requires an appropriate Business Associate Agreement.

Discuss a BAA
How provider access is governedContract controlled
AWSCloud hosting and encrypted storageInfrastructure used to operate n1 and store records securely.BAA in place
AITask-specific AI processingOnly the minimum information required for the processing task is provided.Agreement required
WEBApplication delivery and securityTraffic protection and secure delivery are governed by provider terms and safeguards.Limited purpose
OPSPayments, email and sign-inOperational providers do not receive clinical documents unless their service requires protected data.Data minimised
✓Healthcare organizations can enter into a BAA directly with n1 when n1 acts as their HIPAA business associate.
Security program

Controls at every layer.

EncryptionTLS protects data in transit. Source records and uploaded files stored in n1's production S3 storage are encrypted at rest using AES-256. Document links are signed and expire automatically.
Access controlWorkspace access requires an authenticated account and permissions appropriate to the user's role. Patients may also create time-limited links for individual reports.
Activity recordsSecurity-sensitive activity, including sign-ins, report-sharing actions, and shared-link access, is recorded.
Organizational controlsAccess to production systems is limited to authorized personnel. Staff handling patient data are governed by our privacy and security policies, applicable regional obligations, and customer agreements.
AI & data use

Clear rules for AI.

No training

Your data does not train AI

n1 does not use Customer Patient Data to train general-purpose AI models and does not permit AI providers to do so.

Minimum data

Only what the task needs

The Service sends AI providers the minimum information needed for a task, under service-provider and subprocessor agreements.

Human review

A clinician decides

Qualified human review is required before an output is used in care. n1 supports documentation and preparation — it never makes the clinical decision and is not a diagnostic device.

The record lifecycle

Access, sharing and deletion.

Control who can use a record, what is shared, and what happens when information is no longer needed.

Access

Access follows your controls

Reports and records are available only through authenticated accounts or the sharing controls selected for a specific report.

Export

Take your data with you

Export biomarkers, diagnoses, medications, and more as CSV or Excel, and download any report as PDF or Word.

Deletion

Delete your account

Patients can delete their account directly from settings, with identity re-verification before anything is removed.

Sharing controls

Password · End date · View count · Turn off

Patients can lock report links with a password, set an end date, see how often a link was viewed, and turn it off at any time.

Data requests

Access, correction, deletion

Regional rights to access, correction, deletion, and portability are honored after verification, as described in the Privacy Notice.

Organizational review

Everything your organization needs for review.

For security reviews, procurement, and vendor assessments.

Available documentsSecurity and compliance documentation for vendor assessments — including the hosting SOC 2 Type II attestation and answers to security questionnaires — is available on request. Customers can also request a Data Processing Agreement →
SubprocessorsAWS — cloud hosting and encrypted document storage (handles patient data). Cloudflare — application delivery and TLS (patient data in transit). AI model providers — receive only the minimum data needed per task under service-provider agreements, never for training their models. Read more → Stripe — payments (no clinical data). Postmark — transactional email (no clinical documents). Google — optional sign-in only.
Incident responseIf we identify a reportable breach, we notify affected customers, individuals, or authorities as required by applicable law and contract.
Report a concern

See something? Tell us.

We investigate every report of a potential vulnerability.

Security researchers

longevity@n1.care

Report a suspected vulnerability to longevity@n1.care with steps to reproduce. Do not access, modify, or retain data that is not yours, and do not disrupt the service. We do not operate a bug bounty program.

Customers & patients

Contact us directly

Customers can raise security questions through their n1 contact or the security contact form. Patients should contact their healthcare organization first.

Security FAQ

Questions about data protection.

Direct answers about compliance, encryption, access, retention, and sharing.

Ask a security question →
Who can access patient records?

The clinician who uploads records and the patients they grant access to. Within n1, access to patient data is limited to authorized personnel under least-privilege roles, and access and modification are logged. AI providers receive only the minimum data needed for each processing task, under service-provider agreements, and never for training their models.

Is patient data used to train AI models?

No. n1 does not use Customer Patient Data to train general-purpose AI models and does not permit AI providers to use that data to train their general-purpose models.

Read the AI and training section in our Privacy Notice →

Where is data stored — does it leave my country?

We’re currently working on localised data storage. Contact us if storage in a specific country or region is a requirement for your organization.

Do I need patient consent before uploading records?

That depends on your jurisdiction and role: as the party providing the records, you are responsible for having the authority to do so — through consent, treatment relationship, or another lawful basis your rules recognize. n1 supports this with BAAs, a DPA, and processing strictly on your instructions.

Can n1 run on-premises or self-hosted?

No — n1 is delivered as a managed cloud service.

Is n1.care HIPAA compliant?

Yes, for deployments where HIPAA applies. n1.care supports HIPAA-compliant workflows and maintains Business Associate Agreements (BAAs) with service providers and partners that handle protected health information (PHI) on our behalf. Healthcare organizations can also enter into a BAA directly with n1.

Read the HIPAA information in our Privacy Notice →

Can we complete a security review or questionnaire with n1?

Yes. We answer security questionnaires and provide available documentation — including the hosting SOC 2 Type II attestation — for procurement and vendor assessments. Write to longevity@n1.care or use the security contact form.

Check n1 against your rules.

Tell us what your team needs. We’ll help you review data safety, access, care rules, and launch.