Security
Your Data. Your Rules. Our Commitment.
Last Updated: August 9, 2026
At Arxova™, security is not a feature — it is the foundation. We implement privacy by design at every layer of the stack: from how your data is encrypted, to how it is stored across decentralized infrastructure, to how consent is recorded on-chain. Your health data is yours. We are simply the technology that enforces that.
How We Protect You
Encryption in Transit and at Rest
All health data — whether entered manually, synced from a wearable, or received from your healthcare provider — is encrypted in transit and at rest using industry-standard encryption protocols (AES-256-GCM). Source documents and your ARIA conversations are stored encrypted, with keys held in a secrets system separate from the databases, so a copy of a database alone is unreadable. The structured clinical values extracted from your records — lab results, conditions, medications, visit dates — are stored in queryable form so your scores, charts, and ARIA can function, keyed to a pseudonymous identifier rather than to your name.
Encryption Before Arweave Storage
Health records are always encrypted before they are uploaded to the Arweave network, so the network itself stores an opaque blob and never receives readable health information. For a growing set of records, the encryption key is derived from your own wallet — for those, Arxova cannot decrypt the data. That is not a policy; it is enforced by cryptography. For the remaining records, the key is held by Arxova separately from the databases, which means we are technically able to decrypt them — we do so only to deliver functionality you have asked for, to provide support you request, or where required by law.
Off-Chain Health Data Storage
Sensitive health data is never stored directly on the blockchain. Arxova uses HIPAA-aligned backend infrastructure as the primary data layer, with Arweave available for permanent, user-controlled record storage. The blockchain is never used to store raw health information.
Infrastructure
Three named components sit behind that separation, and each has a single job:
Consent and provenance only. No PHI.
Encrypted blobs. Never readable health data.
Lit ProtocolKey control. Only you decide who can decrypt and view your records.
Blockchain as a Permission & Provenance Ledger
The Solana blockchain records only two things: consent events (when you grant or revoke access to your data) and provenance records (cryptographic proof that a health record exists and that you authorized it). No personal health data is written to or readable from the blockchain. This creates an immutable, auditable trail of your data governance — without exposing anything sensitive publicly.
Revocation by Design
You can terminate any third party's access to your data instantly, at any time, through the app. Every grant and revocation is timestamped and logged on-chain, creating a permanent audit trail. Access is technically enforced — not just policy-based.
Zero Data Selling Policy
We do not sell, rent, trade, or monetize your health data. Period. Data is only shared when you explicitly authorize it, for the specific purpose you approve, with the specific party you select. This applies without exception.
HIPAA-Aligned Infrastructure
Arxova operates on HIPAA-aligned infrastructure, including encrypted dedicated databases, audit logging, and Business Associate Agreements (BAAs) with applicable service providers. Electronic health records received via Fasten Health (FHIR/SMART on FHIR) are handled in strict compliance with HIPAA requirements. A full HIPAA Notice of Privacy Practices is available at arxova.health/hipaa-npp.
Wearable & Third-Party Integration Security
All third-party integrations — including Oura, Withings, Polar, Garmin, Dexcom (via Health Connect), and Apple Health — use secure OAuth 2.0 authentication flows. Access tokens are stored encrypted and never exposed to other users or systems. You can disconnect any integration at any time from within the app, immediately revoking Arxova's access to that data source.
The Evidence
The architecture above is not a preference. These are the peer-reviewed findings it is built on — on what fragmented records cost patients, and on what this class of technology has been shown to do for record integrity, access control, and auditability.
Peer-reviewed evidence · 2021–2023
Among Medicare beneficiaries, fragmented hospital readmissions — when patients are readmitted to a different hospital than where they were originally discharged — are associated with worse discharge outcomes. Shared electronic information between hospitals significantly improves the odds of recovering at home.
When the admission and readmission hospital shared a health information exchange, beneficiaries had 9–15% higher odds of being discharged home with home health.
Turbow SD, Uppal T, Chehal PK, et al. Association of Fragmented Readmissions and Electronic Information Sharing With Discharge Destination Among Older Adults. JAMA Network Open. JAMA Netw Open. 2023;6(5):e2313592.View ↗
Compliance & Standards
- Arxova (HealthKey Labs LLC) is an approved participant in the CMS Health Tech Ecosystem, in the Conversational AI Assistants and Kill the Clipboard categories. Participation is not a CMS endorsement.
- We align with HIPAA and GDPR best practices across all data handling operations.
- We execute Business Associate Agreements (BAAs) with all applicable service providers.
- We regularly audit our systems for vulnerabilities and apply security patches promptly.
- We enforce strict partner requirements: No explicit user consent = No data access. No exceptions.
- On-chain permission records provide an immutable, third-party-verifiable audit trail of every consent event.
- In the event of a data breach affecting your personal or health information, we will notify affected users in accordance with HIPAA's Breach Notification Rule and other applicable law.
Responsible Disclosure
If you discover a security vulnerability in Arxova's platform, please report it responsibly. Contact us directly at contact@arxova.health with a detailed description of the issue before any public disclosure. We are committed to investigating and addressing all reported vulnerabilities promptly and transparently. We will not pursue legal action against researchers who report vulnerabilities in good faith and in accordance with this policy.
Contact Us
Email: contact@arxova.health
Website: www.arxova.health
Operated by: HealthKey Labs, LLC d/b/a Arxova™
Address: 382 NE 191st St PMB #924568, Miami, FL 33179
Patent Pending — Serial No. 64/010,350 | Arxova™ is a trademark of HealthKey Labs, LLC