Trust & compliance

Your health data deserves the highest standard of care.

Nova is engineered to meet the operational, security and regulatory requirements of modern healthcare organizations in Kenya. From encryption and access controls to audit logging and resilient cloud infrastructure, every layer of the platform is designed with security, privacy and reliability in mind. Protecting health information is a shared responsibility. Crucibel is responsible for securing, maintaining and continuously improving the Nova platform, while healthcare organizations remain responsible for user administration, role-based access configuration, patient consent management and compliance with applicable legal and regulatory obligations within their own facilities.

For questions about our security practices, compliance posture, or to request copies of our policies and governance documents, contact our team.

Kenya Data Protection Act

Designed to support compliance with the Data Protection Act, 2019 and applicable healthcare privacy obligations.

ODPC Certified

Crucibel is certified by the ODPC, demonstrating our commitment to responsible personal data processing and regulatory compliance.

Encryption in Transit & at Rest

All patient data is protected using industry-standard encryption both during transmission and while stored.

Comprehensive Audit Trails

Access to patient information and other sensitive actions are logged to support accountability, monitoring and compliance.

Role-Based Access Control

Granular permissions ensure users can access only the information necessary for their responsibilities.

Data Residency

Customer data is hosted in locations selected to support Kenyan data protection requirements and customer obligations.

Operational Resilience

Backups, continuous monitoring and incident response processes help ensure the availability and resilience of the Nova platform.

Consent & Information Governance

Supports patient consent workflows and controlled sharing of health information across authorized healthcare providers.

Vendor & Subprocessor Governance

Third-party service providers undergo security and privacy due diligence before being entrusted with customer data.

Data protection

We take the responsibility of handling health data seriously.

As a healthcare technology company, Crucibel may operate as both a Data Controller and Data Processor depending on the nature of the processing activity and the relationship with our customers and partners. Our registration with the Office of the Data Protection Commissioner reflects our commitment to responsible data governance and to protecting the rights and privacy of individuals whose information is processed through our systems.

Data ControllerData Processor

Shared responsibility

Security and compliance work best when responsibility is shared.

Crucibel is responsible for securing, maintaining and continuously improving the Nova platform and its underlying infrastructure.

Healthcare organizations using Nova remain responsible for how they configure and use the platform, including user administration, access management, internal policies, patient consent processes and compliance obligations applicable to their own operations.