Security
Security is a top priority at Noterro, and we understand the importance of keeping your data safe. We have implemented a comprehensive set of security measures to ensure that your data is protected. In this section, we will discuss the various security measures we have in place, emphasizing our commitment to data security.
Encryption
Encryption plays a critical role in safeguarding your data. We employ advanced encryption methods to ensure that your data remains secure both during transit and at rest. By encrypting your data, we add an additional layer of protection, making it extremely difficult for unauthorized individuals to access or decipher your sensitive information. Our encryption practices adhere to industry standards and best practices, ensuring the highest level of security for your data.
Backups
We also understand the importance of data integrity and the need for reliable backups. To address this, we maintain regular backups of your data in multiple physical data centers. This redundancy ensures that even in the event of a hardware failure or other unforeseen circumstances, your data remains intact and accessible. Our backup strategy is designed to provide peace of mind, knowing that your valuable data is continuously protected and available when you need it.
Monitoring
Threat monitoring and detection are essential aspects of our security framework. We have systems in place that continuously monitor our systems 24/7. These teams employ sophisticated tools and techniques to detect any potential threats or suspicious activities in real-time. By leveraging proactive monitoring, we can identify and mitigate risks before they can cause any harm. Our web traffic firewall acts as a gatekeeper, preventing unauthorized access attempts and shielding your data from malicious actors. In addition, we utilize network firewalls and isolation mechanisms to fortify our infrastructure against potential breaches.
Security by Design
Security is an integral part of our software development process, and we adhere to a DevSecOps approach. This means that security is integrated into every step of our development lifecycle. Our development team follows the principle of “security by design,” ensuring that security considerations are incorporated from the early stages of product design. We employ various security testing techniques, such as Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST), to identify and address potential vulnerabilities. Every code change made goes through a rigorous review and approval process by multiple team members, ensuring that no vulnerabilities are introduced into the production environment.
Access Controls
To further enhance security, we strictly enforce the principle of least privilege and separation of duties. This means that only authorized personnel have access to your data, and access rights are granted on a need-to-know basis. By limiting access to your data to only those who require it, we significantly reduce the risk of unauthorized access or data breaches.
In Summary
At Noterro, we are fully committed to providing the highest level of security for your data. Our security measures are designed with meticulous attention to detail, ensuring that your data remains safe and protected. By employing encryption, maintaining backups, monitoring for threats, following a DevSecOps approach, and enforcing strict access controls, we create a robust security posture. You can have complete confidence in our platform, knowing that your data is in safe hands with us. We take your data security seriously, and we continuously strive to stay ahead of emerging threats and industry best practices. With us, your data is seriously safe.
We’ve got answers!
Noterro is typically updated several times per week. Each update includes automated SCA (analysis of third-party code), SAST (analysis of first-party code), DAST (analysis of a running version of the code) as well as multiple human-level reviews.
The Admin of the clinic is able to submit a delete request, which will be reviewed by our team and executed. This will permanently delete patient-related data from our databases.
Sensitive information is only ever transmitted over encrypted connections and stored at rest in an encrypted state.
Clinic data is stored in Canada. Noterro Scribe recordings are temporarily stored in the United States during processing and automatically deleted afterwards.