Data Security & Privacy

Your family's health information deserves real protection

Evera holds some of the most personal information your family has: your children's vaccine records, your medications, your insurance cards, your appointments. We take that seriously, and we think you deserve a plain-language explanation of exactly how it's protected rather than a badge and a promise.

Here's how Evera is built.

Encryption

In transit. Every connection between the Evera app and our servers is encrypted using TLS, the same standard (the "https" in your browser) used by banking apps and major websites. Evera's own code enforces secure connections, in addition to the protections our hosting providers apply.

At rest. All data stored in our database is encrypted at rest. Uploaded documents and images, including vaccine cards and insurance cards, are also encrypted at rest.

Infrastructure

Evera runs on established infrastructure providers that hold independent, third-party-audited security certifications:

  • Our database provider maintains SOC 2 Type II, ISO 27001, ISO 27701, and HIPAA compliance

  • Our hosting provider maintains SOC 2 Type II, SOC 3, and HIPAA compliance under a shared-responsibility mode

These certifications mean independent auditors have verified that these companies follow rigorous, recognized security practices, the same standards that banks and healthcare organizations require of their technology vendors.

All Evera user data is stored in US-based data centers.

A note on precision: these certifications belong to the infrastructure Evera is built on. Evera itself has not yet completed its own SOC 2 audit.

Accounts and access

Passwords. Your password is never stored in a readable form. Evera uses bcrypt, an industry-standard one-way hashing method built specifically for password storage. No one at Evera or on our development team can see or recover your actual password.

Sessions. Signing out or resetting a forgotten password invalidates previous access tokens. Password reset codes expire after 15 minutes.

Internal access. Access to Evera's live database and hosting environment is restricted to a single authorized engineer. There is no broader team access to user data.

The services Evera uses, and what each one receives

Evera relies on a small number of established third-party services to power specific features. None of them receives more information than it needs to do its job:

‍ Your data belongs to you

We do not sell your data. We do not share it for advertising. Ever. Evera makes money from subscriptions, not from your information, and we intend to keep it that way.

You can export your data. All of it, whenever you want.

You can delete your account. When you do, your profile, medical, and appointment data is permanently deleted from our database, along with every document and image you've uploaded. Deleted means deleted.

Children's information

Evera holds health information about children, so this deserves its own explanation.

Children don't have Evera accounts. Parents and caregivers do. A child's profile is created and managed by the adult who cares for them, within that adult's account. There is no child-facing login, no child-directed content, and we collect nothing directly from children.

At signup, every account holder confirms they meet our minimum age requirement. Accounts are for adults managing their family's care.

A child's information is protected exactly the same way every other profile is: encrypted in transit and at rest, stored in US data centers, never sold, never shared for advertising, and deletable by you at any time.

If something ever went wrong

As a consumer health app, Evera operates under the FTC's Health Breach Notification Rule, which requires notifying affected users within 60 days if health information is ever exposed. We've built our internal logging specifically to support fast, accurate investigation if that ever became necessary.

We hope never to use it. We'd rather have it ready.

What we're working on next

Security isn't a finish line. Here's what's on our roadmap:

  • Formal data processing agreements with each of our service providers

  • Automated monitoring and alerting for unusual account activity

  • Enforced two-factor authentication across all infrastructure accounts

  • Automated vulnerability scanning for our software dependencies

  • A published data retention policy for long-inactive accounts

  • Additional redundancy for stored documents

  • A third-party penetration test, and eventually our own SOC 2 audit

We'll update this page as each of these is completed.

Questions?

If you have a question about how Evera protects your family's information, or you've found something you think we should know about, email hello@everahealth.co and we'll respond personally.

Last updated: August 2026