Health data you can trust.
Choose whether the source file remains.
Encrypted in transit and at rest.
TLS
AES-256
Access follows the user’s role.
Important activity leaves a trail.
Share only when it is ready.
Built around recognized safeguards.
Your records stay protected
Encrypted during transfer and storage, with short-lived document links.
Built on trusted hosting
Hosted on infrastructure certified to SOC 2 Type II.
Your data is not the product
No sale of patient data or use for targeted advertising. Read more →
Ready for HIPAA workflows
Appropriate safeguards and Business Associate Agreements where HIPAA applies.
Protection extends to the providers we use.
Providers receive only the information needed to deliver their service. When a provider handles protected health information on our behalf, n1 requires an appropriate Business Associate Agreement.
Discuss a BAAControls at every layer.
Clear rules for AI.
Your data does not train AI
n1 does not use Customer Patient Data to train general-purpose AI models and does not permit AI providers to do so.
Only what the task needs
The Service sends AI providers the minimum information needed for a task, under service-provider and subprocessor agreements.
A clinician decides
Qualified human review is required before an output is used in care. n1 supports documentation and preparation — it never makes the clinical decision and is not a diagnostic device.
Access, sharing and deletion.
Control who can use a record, what is shared, and what happens when information is no longer needed.
Access follows your controls
Reports and records are available only through authenticated accounts or the sharing controls selected for a specific report.
Take your data with you
Export biomarkers, diagnoses, medications, and more as CSV or Excel, and download any report as PDF or Word.
Delete your account
Patients can delete their account directly from settings, with identity re-verification before anything is removed.
Password · End date · View count · Turn off
Patients can lock report links with a password, set an end date, see how often a link was viewed, and turn it off at any time.
Access, correction, deletion
Regional rights to access, correction, deletion, and portability are honored after verification, as described in the Privacy Notice.
Everything your organization needs for review.
For security reviews, procurement, and vendor assessments.
See something? Tell us.
We investigate every report of a potential vulnerability.
longevity@n1.care
Report a suspected vulnerability to longevity@n1.care with steps to reproduce. Do not access, modify, or retain data that is not yours, and do not disrupt the service. We do not operate a bug bounty program.
Contact us directly
Customers can raise security questions through their n1 contact or the security contact form. Patients should contact their healthcare organization first.
Questions about data protection.
Direct answers about compliance, encryption, access, retention, and sharing.
Ask a security question →Who can access patient records?
The clinician who uploads records and the patients they grant access to. Within n1, access to patient data is limited to authorized personnel under least-privilege roles, and access and modification are logged. AI providers receive only the minimum data needed for each processing task, under service-provider agreements, and never for training their models.
Is patient data used to train AI models?
No. n1 does not use Customer Patient Data to train general-purpose AI models and does not permit AI providers to use that data to train their general-purpose models.
Read the AI and training section in our Privacy Notice →
Where is data stored — does it leave my country?
We’re currently working on localised data storage. Contact us if storage in a specific country or region is a requirement for your organization.
Do I need patient consent before uploading records?
That depends on your jurisdiction and role: as the party providing the records, you are responsible for having the authority to do so — through consent, treatment relationship, or another lawful basis your rules recognize. n1 supports this with BAAs, a DPA, and processing strictly on your instructions.
Can n1 run on-premises or self-hosted?
No — n1 is delivered as a managed cloud service.
Is n1.care HIPAA compliant?
Yes, for deployments where HIPAA applies. n1.care supports HIPAA-compliant workflows and maintains Business Associate Agreements (BAAs) with service providers and partners that handle protected health information (PHI) on our behalf. Healthcare organizations can also enter into a BAA directly with n1.
Read the HIPAA information in our Privacy Notice →
Can we complete a security review or questionnaire with n1?
Yes. We answer security questionnaires and provide available documentation — including the hosting SOC 2 Type II attestation — for procurement and vendor assessments. Write to longevity@n1.care or use the security contact form.
Check n1 against your rules.
Tell us what your team needs. We’ll help you review data safety, access, care rules, and launch.