Data Security & Privacy
Your family's health information deserves real protection
Evera holds some of the most personal information your family has: your children's vaccine records, your medications, your insurance cards, your appointments. We take that seriously, and we think you deserve a plain-language explanation of exactly how it's protected rather than a badge and a promise.
Here's how Evera is built.
Encryption
In transit. Every connection between the Evera app and our servers is encrypted using TLS, the same standard (the "https" in your browser) used by banking apps and major websites. Evera's own code enforces secure connections, in addition to the protections our hosting providers apply.
At rest. All data stored in our database is encrypted at rest. Uploaded documents and images, including vaccine cards and insurance cards, are also encrypted at rest.
Infrastructure
Evera runs on established infrastructure providers that hold independent, third-party-audited security certifications:
Our database provider maintains SOC 2 Type II, ISO 27001, ISO 27701, and HIPAA compliance
Our hosting provider maintains SOC 2 Type II, SOC 3, and HIPAA compliance under a shared-responsibility mode
These certifications mean independent auditors have verified that these companies follow rigorous, recognized security practices, the same standards that banks and healthcare organizations require of their technology vendors.
All Evera user data is stored in US-based data centers.
A note on precision: these certifications belong to the infrastructure Evera is built on. Evera itself has not yet completed its own SOC 2 audit.
Accounts and access
Passwords. Your password is never stored in a readable form. Evera uses bcrypt, an industry-standard one-way hashing method built specifically for password storage. No one at Evera or on our development team can see or recover your actual password.
Sessions. Signing out or resetting a forgotten password invalidates previous access tokens. Password reset codes expire after 15 minutes.
Internal access. Access to Evera's live database and hosting environment is restricted to a single authorized engineer. There is no broader team access to user data.
The services Evera uses, and what each one receives
Evera relies on a small number of established third-party services to power specific features. None of them receives more information than it needs to do its job:
Your data belongs to you
We do not sell your data. We do not share it for advertising. Ever. Evera makes money from subscriptions, not from your information, and we intend to keep it that way.
You can export your data. All of it, whenever you want.
You can delete your account. When you do, your profile, medical, and appointment data is permanently deleted from our database, along with every document and image you've uploaded. Deleted means deleted.
Children's information
Evera holds health information about children, so this deserves its own explanation.
Children don't have Evera accounts. Parents and caregivers do. A child's profile is created and managed by the adult who cares for them, within that adult's account. There is no child-facing login, no child-directed content, and we collect nothing directly from children.
At signup, every account holder confirms they meet our minimum age requirement. Accounts are for adults managing their family's care.
A child's information is protected exactly the same way every other profile is: encrypted in transit and at rest, stored in US data centers, never sold, never shared for advertising, and deletable by you at any time.
If something ever went wrong
As a consumer health app, Evera operates under the FTC's Health Breach Notification Rule, which requires notifying affected users within 60 days if health information is ever exposed. We've built our internal logging specifically to support fast, accurate investigation if that ever became necessary.
We hope never to use it. We'd rather have it ready.
What we're working on next
Security isn't a finish line. Here's what's on our roadmap:
Formal data processing agreements with each of our service providers
Automated monitoring and alerting for unusual account activity
Enforced two-factor authentication across all infrastructure accounts
Automated vulnerability scanning for our software dependencies
A published data retention policy for long-inactive accounts
Additional redundancy for stored documents
A third-party penetration test, and eventually our own SOC 2 audit
We'll update this page as each of these is completed.
Questions?
If you have a question about how Evera protects your family's information, or you've found something you think we should know about, email hello@everahealth.co and we'll respond personally.
Last updated: August 2026