Security controls
Encryption and key management
What is encrypted, with what, and who holds keys.
How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration
C0140Is sensitive data encrypted in the pilot?
Field-level AES-GCM protects Social Security numbers, MFA secrets and registration change history under a secret held by the hosting platform. Rotation, per-tenant keys and a key service are not in place.
C0141Which algorithms does the production design use?
Strong, standard ones: AES-256 for stored data, SHA-256 hashing, ECDSA or Ed25519 signatures, TLS 1.3, and a hybrid X25519 plus ML-KEM key exchange for quantum resistance. Nothing custom is used for confidentiality.
C0142Are keys ever visible to administrators?
The design says no: keys live in a hardware module or sealed chip, are never exported in plaintext, and are released only to the application after an attested policy decision.
C0143What if a key is lost?
Split custody with named custodians, a scripted ceremony and an annual recovery test are designed. Nothing of this exists in the pilot.
C0144How often are keys rotated?
Intervals are an open item. The design proposes scheduled rotation and rewrap without downtime.
C0145Is post-quantum cryptography planned?
Yes for key exchange via a hybrid scheme and through large symmetric keys for stored data. Post-quantum signatures are optional and open.
C0146Is there protection against harvest-now-decrypt-later?
Hybrid key establishment is adopted early in the design, because medical data stays sensitive for decades.
C0147Does AuroraMed use homemade cryptography?
The design requires proven primitives and audited libraries, and treats decoy traffic as traffic-analysis resistance only, not as encryption.
C0148Where do encryption keys sit for small clinics?
Sealed to the server's security chip or a smartcard token; larger sites use a validated hardware module. Product choices are open.
C0149Can data be recovered if the clinic loses its keys?
Escrowed key material under split custody is part of the backup design. It is designed, not built.