Security overview
Updated August 3, 2026. Written in plain language on purpose.
Where patient data lives
Patient records stay in your billing system. QuickBooks receives accounting summaries only: journal entries by location and service line, never patient records. Inside Nielo, patient references are tokenized: shown as neutral codes such as PT-129F34 rather than names, until a verified user deliberately unlocks the view.
What "tokenized" means here
A token is a stand-in code. Screens render the code instead of the patient reference, so someone walking past a monitor, a screen share, or a stray screenshot sees codes, not people. Unlocking the real view requires a fresh passkey verification, and the view re-locks when you leave the page or after ten minutes without activity.
Sign-in
- Every account signs in with a password plus a passkey. Passkeys use asymmetric cryptography, are bound to the Nielo domain so look-alike sites can't use them, and require your fingerprint, face, or device PIN.
- There are no authenticator codes, SMS codes, or backup codes anywhere in the product; those channels are phishable, so they don't exist.
- Every account enrolls two passkeys on two different devices, so a lost device never locks the account and never forces a weaker recovery path.
- Failed sign-in attempts are rate limited and logged.
Sensitive changes and recovery
- Adding or removing a passkey and changing a sign-in email require a fresh passkey verification. Email changes additionally require a confirmation link that only works in the browser that requested the change.
- Account recovery is performed by Nielo staff and gated by a mandatory identity checklist, including a call back to the phone number on file. There are no reset links or codes to phish. A recovery removes the account's passkeys, ends its sessions, and requires fresh enrollment.
Data in transit and at rest
- All traffic is encrypted in transit over TLS.
- Application data is stored on access-controlled infrastructure; production access is limited to Nielo staff with a need, behind the same passkey requirements described above.
Compliance posture
Nielo is in its pilot phase. We do not claim SOC 2 certification or third-party audit completion today, and we won't imply otherwise. Compliance documentation, business associate agreement discussion, and architecture review are part of pilot diligence with every customer. Ask for whatever your compliance process needs.
Reporting a concern
Security questions or reports: [email protected]. We respond to security reports as a priority.