/ SECURITY

HIPAA-aligned defaults
from day one.

Built like the audits are coming Monday — because they are. Security isn't a settings page in Convey; it's the foundation everything else sits on. And it's post-quantum-safe, built to meet the federal CNSA 2.0 standards taking effect January 1, 2027.

POST-QUANTUM ENCRYPTION

Post-quantum-safe, at rest + in transit

AES-256 for message bodies and TLS 1.3 with hybrid post-quantum key exchange (NIST FIPS 203 ML-KEM) in flight. Keys never leave the secure enclave.

AUDITING

Per-patient audit

Every read of every section logged. Answer "who saw what" in a single query, for your org or a partner's.

ACCESS CONTROL

Role + scope control

Org admins gate sections by role; partner admins gate by network scope. Least-privilege by default.

TENANCY

Your data, your tenant

Single-tenant data plane per organization. Export anytime — your record is yours to take with you.

POST-QUANTUM READY

Ready for the federal 2027 post-quantum mandate.

Convey's cryptography follows NIST's post-quantum standards — FIPS 203 (ML-KEM) for key establishment and FIPS 204 (ML-DSA) for digital signatures — alongside AES-256. That aligns us with the NSA's Commercial National Security Algorithm Suite (CNSA 2.0), which every new National Security System acquisition must support starting January 1, 2027. Government partners get quantum-resistant protection today, ahead of the deadline.

Post-quantum-safeCNSA 2.0 alignedNIST FIPS 203 / 204AES-256HIPAA-alignedSOC 2 in progress
© 2026 Convey, Inc.