Security

Your Data. Your Rules. Our Commitment.

Last Updated: August 9, 2026

At Arxova™, security is not a feature — it is the foundation. We implement privacy by design at every layer of the stack: from how your data is encrypted, to how it is stored across decentralized infrastructure, to how consent is recorded on-chain. Your health data is yours. We are simply the technology that enforces that.

How We Protect You

Encryption in Transit and at Rest

All health data — whether entered manually, synced from a wearable, or received from your healthcare provider — is encrypted in transit and at rest using industry-standard encryption protocols (AES-256-GCM). Source documents and your ARIA conversations are stored encrypted, with keys held in a secrets system separate from the databases, so a copy of a database alone is unreadable. The structured clinical values extracted from your records — lab results, conditions, medications, visit dates — are stored in queryable form so your scores, charts, and ARIA can function, keyed to a pseudonymous identifier rather than to your name.

Encryption Before Arweave Storage

Health records are always encrypted before they are uploaded to the Arweave network, so the network itself stores an opaque blob and never receives readable health information. For a growing set of records, the encryption key is derived from your own wallet — for those, Arxova cannot decrypt the data. That is not a policy; it is enforced by cryptography. For the remaining records, the key is held by Arxova separately from the databases, which means we are technically able to decrypt them — we do so only to deliver functionality you have asked for, to provide support you request, or where required by law.

Off-Chain Health Data Storage

Sensitive health data is never stored directly on the blockchain. Arxova uses HIPAA-aligned backend infrastructure as the primary data layer, with Arweave available for permanent, user-controlled record storage. The blockchain is never used to store raw health information.

Blockchain as a Permission & Provenance Ledger

The Solana blockchain records only two things: consent events (when you grant or revoke access to your data) and provenance records (cryptographic proof that a health record exists and that you authorized it). No personal health data is written to or readable from the blockchain. This creates an immutable, auditable trail of your data governance — without exposing anything sensitive publicly.

Revocation by Design

You can terminate any third party's access to your data instantly, at any time, through the app. Every grant and revocation is timestamped and logged on-chain, creating a permanent audit trail. Access is technically enforced — not just policy-based.

Zero Data Selling Policy

We do not sell, rent, trade, or monetize your health data. Period. Data is only shared when you explicitly authorize it, for the specific purpose you approve, with the specific party you select. This applies without exception.

HIPAA-Aligned Infrastructure

Arxova operates on HIPAA-aligned infrastructure, including encrypted dedicated databases, audit logging, and Business Associate Agreements (BAAs) with applicable service providers. Electronic health records received via Fasten Health (FHIR/SMART on FHIR) are handled in strict compliance with HIPAA requirements. A full HIPAA Notice of Privacy Practices is available at arxova.health/hipaa-npp.

Wearable & Third-Party Integration Security

All third-party integrations — including Oura, Withings, Polar, Garmin, Dexcom (via Health Connect), and Apple Health — use secure OAuth 2.0 authentication flows. Access tokens are stored encrypted and never exposed to other users or systems. You can disconnect any integration at any time from within the app, immediately revoking Arxova's access to that data source.

Compliance & Standards

  • Arxova (HealthKey Labs LLC) is an approved participant in the CMS Health Tech Ecosystem, in the Conversational AI Assistants and Kill the Clipboard categories. Participation is not a CMS endorsement.
  • We align with HIPAA and GDPR best practices across all data handling operations.
  • We execute Business Associate Agreements (BAAs) with all applicable service providers.
  • We regularly audit our systems for vulnerabilities and apply security patches promptly.
  • We enforce strict partner requirements: No explicit user consent = No data access. No exceptions.
  • On-chain permission records provide an immutable, third-party-verifiable audit trail of every consent event.
  • In the event of a data breach affecting your personal or health information, we will notify affected users in accordance with HIPAA's Breach Notification Rule and other applicable law.

Responsible Disclosure

If you discover a security vulnerability in Arxova's platform, please report it responsibly. Contact us directly at contact@arxova.health with a detailed description of the issue before any public disclosure. We are committed to investigating and addressing all reported vulnerabilities promptly and transparently. We will not pursue legal action against researchers who report vulnerabilities in good faith and in accordance with this policy.

Contact Us

Email: contact@arxova.health

Website: www.arxova.health

Operated by: HealthKey Labs, LLC d/b/a Arxova™

Address: 382 NE 191st St PMB #924568, Miami, FL 33179

Patent Pending — Serial No. 64/010,350 | Arxova™ is a trademark of HealthKey Labs, LLC