← Tuvy

Data & Security

Last updated: 17 September 2026
Questions or disclosures: admin@tuvy.health

Tuvy holds health information about people who are often not the person operating the app. That asymmetry is the reason for most of what follows.

Encryption

Who can see what

The visit record

Each visit builds a SHA-256 hash chain: every recorded event includes the hash of the one before it, so an event cannot be altered or removed after the fact without breaking the chain. The family receives the resulting certificate.

Where your data lives

Our services run on Google Cloud in the United States (Iowa). Health data about care recipients in India is therefore stored and processed in the US. This is stated plainly in our Privacy Policy, and it is a deliberate disclosure rather than a detail.

Operational practice

What we do not claim

Security pages usually list only strengths. These are the things we are asked about that we cannot yet answer with a yes:

  • We are not SOC 2 certified. We maintain a control evidence map internally, which is preparation for an audit — not the same as having passed one.
  • Face capture is not yet face recognition. We photograph both caregiver and patient at the door and seal those captures into the visit record. We do not currently match a face against an enrolled photograph, and we do not perform liveness detection. We will say so here when that changes.
  • We have not completed an independent penetration test. The scope is defined; the test has not been carried out.

If any of this matters to a decision you are making, ask us directly and we will tell you where things actually stand.

Reporting a vulnerability

Email admin@tuvy.health with enough detail to reproduce the issue. We will acknowledge it, and we will not pursue anyone who reports a genuine finding in good faith and does not access or alter other people's data while investigating.