Trust & Responsibility

Clear Commitments, Verified Claims

Nexora distinguishes public website information from contracted security, privacy and compliance obligations.

Public Website

Public forms are not intended for PHI. Essential preferences are stored locally; analytics requires approved configuration.

Contracted Controls

Access, systems, data handling, subcontractors and responsibilities must be documented in applicable agreements.

Responsible Claims

No certification, HIPAA compliance badge, client outcome or security claim is published without verification.

Website Protections

  • HTTPS enforcement preparation
  • Security and referrer headers
  • Restricted directory listing
  • Form validation, honeypot and rate limiting
  • No public portal credential collection

Privacy Choices

  • Essential-only browser storage choice
  • Clear SMS consent separation
  • No sale of personal information
  • Contact channel for privacy requests

Before Client Go-Live

  • Confirm approved systems and roles
  • Complete agreements and access controls
  • Verify incident/escalation contacts
  • Document secure exchange process