Security
Your Data. Your Rules. Our Commitment.
Last Updated: April 4, 2026
At Arxova™, security is not a feature — it is the foundation. We implement privacy by design at every layer of the stack: from how your data is encrypted on your device, to how it is stored across decentralized infrastructure, to how consent is recorded on-chain. Your health data is yours. We are simply the technology that enforces that.
How We Protect You
End-to-End Encryption
All health data — whether entered manually, synced from a wearable, or received from your healthcare provider — is encrypted in transit and at rest using industry-standard encryption protocols. Your data is never transmitted or stored in plaintext.
On-Device Encryption Before Arweave Storage
When you choose to permanently store health records on the Arweave network, your data is encrypted on your device before it ever leaves. Only you hold the decryption key. Arxova cannot read, access, modify, or delete data stored on Arweave. This is not a policy — it is a technical guarantee enforced by cryptography.
Off-Chain Health Data Storage
Sensitive health data is never stored directly on the blockchain. Arxova uses HIPAA-compliant backend infrastructure as the primary data layer, with Arweave available for permanent, user-controlled record storage. The blockchain is never used to store raw health information.
Blockchain as a Permission & Provenance Ledger
The Solana blockchain records only two things: consent events (when you grant or revoke access to your data) and provenance records (cryptographic proof that a health record exists and that you authorized it). No personal health data is written to or readable from the blockchain. This creates an immutable, auditable trail of your data governance — without exposing anything sensitive publicly.
Revocation by Design
You can terminate any third party's access to your data instantly, at any time, through the app. Every grant and revocation is timestamped and logged on-chain, creating a permanent audit trail. Access is technically enforced — not just policy-based.
Zero Data Selling Policy
We do not sell, rent, trade, or monetize your health data. Period. Data is only shared when you explicitly authorize it, for the specific purpose you approve, with the specific party you select. This applies without exception.
HIPAA-Compliant Infrastructure
Arxova operates on HIPAA-compliant infrastructure, including encrypted dedicated databases, audit logging, and Business Associate Agreements (BAAs) with applicable service providers. Electronic health records received via Fasten Health (FHIR/SMART on FHIR) are handled in strict compliance with HIPAA requirements. A full HIPAA Notice of Privacy Practices is available at arxova.health/hipaa-npp.
Wearable & Third-Party Integration Security
All third-party integrations — including Oura, Withings, Polar, Garmin, Dexcom (via Health Connect), and Apple Health — use secure OAuth 2.0 authentication flows. Access tokens are stored encrypted and never exposed to other users or systems. You can disconnect any integration at any time from within the app, immediately revoking Arxova's access to that data source.
MoonPay Payment Security
Arxova does not handle, process, or store fiat payment information or identity documents. All fiat on-ramp and off-ramp transactions are processed exclusively by MoonPay, a licensed, regulated financial services provider. Arxova never sees your payment credentials.
Compliance & Standards
- We align with HIPAA and GDPR best practices across all data handling operations.
- We execute Business Associate Agreements (BAAs) with all applicable service providers.
- We regularly audit our systems for vulnerabilities and apply security patches promptly.
- We enforce strict partner requirements: No explicit user consent = No data access. No exceptions.
- On-chain permission records provide an immutable, third-party-verifiable audit trail of every consent event.
- In the event of a data breach affecting your personal or health information, we will notify affected users in accordance with HIPAA's Breach Notification Rule and other applicable law.
Responsible Disclosure
If you discover a security vulnerability in Arxova's platform, please report it responsibly. Contact us directly at contact@arxova.health with a detailed description of the issue before any public disclosure. We are committed to investigating and addressing all reported vulnerabilities promptly and transparently. We will not pursue legal action against researchers who report vulnerabilities in good faith and in accordance with this policy.
Contact Us
Email: contact@arxova.health
Website: www.arxova.health
Operated by: HealthKey Labs, LLC d/b/a Arxova™
Address: 382 NE 191st St PMB #924568, Miami, FL 33179
Patent Pending — Serial No. 64/010,350 | Arxova™ is a trademark of HealthKey Labs, LLC