HIPAA-aligned defaults
from day one.
Built like the audits are coming Monday — because they are. Security isn't a settings page in Convey; it's the foundation everything else sits on. And it's post-quantum-safe, built to meet the federal CNSA 2.0 standards taking effect January 1, 2027.
Post-quantum-safe, at rest + in transit
AES-256 for message bodies and TLS 1.3 with hybrid post-quantum key exchange (NIST FIPS 203 ML-KEM) in flight. Keys never leave the secure enclave.
Per-patient audit
Every read of every section logged. Answer "who saw what" in a single query, for your org or a partner's.
Role + scope control
Org admins gate sections by role; partner admins gate by network scope. Least-privilege by default.
Your data, your tenant
Single-tenant data plane per organization. Export anytime — your record is yours to take with you.
Ready for the federal 2027 post-quantum mandate.
Convey's cryptography follows NIST's post-quantum standards — FIPS 203 (ML-KEM) for key establishment and FIPS 204 (ML-DSA) for digital signatures — alongside AES-256. That aligns us with the NSA's Commercial National Security Algorithm Suite (CNSA 2.0), which every new National Security System acquisition must support starting January 1, 2027. Government partners get quantum-resistant protection today, ahead of the deadline.