Data & Security
Tuvy holds health information about people who are often not the person operating the app. That asymmetry is the reason for most of what follows.
Encryption
- At rest. Health and identifying fields are encrypted with AES-256-GCM in our application layer before they reach the database, so the stored value is ciphertext rather than readable text.
- In transit. All traffic between the apps and our services runs over TLS.
- Keys are held in Google Secret Manager and loaded at runtime. They are not in our source code.
Who can see what
- Every protected endpoint enforces role-based access control — family member, care professional, and operations are separate roles with separate reach.
- Within a family, each member has a per-member visibility setting. Fields a member has not been granted are removed before the data leaves our servers, not hidden in the app.
- A newly invited family member starts with no visibility until the account owner grants it.
The visit record
Each visit builds a SHA-256 hash chain: every recorded event includes the hash of the one before it, so an event cannot be altered or removed after the fact without breaking the chain. The family receives the resulting certificate.
Where your data lives
Our services run on Google Cloud in the United States (Iowa). Health data about care recipients in India is therefore stored and processed in the US. This is stated plainly in our Privacy Policy, and it is a deliberate disclosure rather than a detail.
Operational practice
- Database backups run automatically.
- Care professionals pass government-ID document checks, professional registry checks, police clearance and a manual operations review before they can be matched.
- Secrets are rotated through Secret Manager rather than redeployed in code.
What we do not claim
Security pages usually list only strengths. These are the things we are asked about that we cannot yet answer with a yes:
- We are not SOC 2 certified. We maintain a control evidence map internally, which is preparation for an audit — not the same as having passed one.
- Face capture is not yet face recognition. We photograph both caregiver and patient at the door and seal those captures into the visit record. We do not currently match a face against an enrolled photograph, and we do not perform liveness detection. We will say so here when that changes.
- We have not completed an independent penetration test. The scope is defined; the test has not been carried out.
If any of this matters to a decision you are making, ask us directly and we will tell you where things actually stand.
Reporting a vulnerability
Email admin@tuvy.health with enough detail to reproduce the issue. We will acknowledge it, and we will not pursue anyone who reports a genuine finding in good faith and does not access or alter other people's data while investigating.