Security
Mana handles patient data like a clinician would: encrypted, role-gated, audited, and hosted with New Zealand clinics in mind. Aligned with the Privacy Act 2020 and the Health Information Privacy Code.
Privacy Act 2020 · NZHealth Information Privacy CodeEncryption at rest & in transit
mana / security · controls
AES-256 at rest · TLS 1.3 in transit
Role-based access · SSO available on Clinic (8+)
Immutable audit trail · exportable
Data residency: New Zealand · encrypted backups
Regular independent security testing
Privacy
Privacy Act 2020 & HIPC
Aligned with the NZ Privacy Act 2020 and the Health Information Privacy Code for health agencies.
Residency
Data residency
Patient data stored securely for NZ clinics, with encrypted backups. Residency details on request.
Audit
Audit logs
Every action — agent or human — is logged with actor, time, and reason. Exportable CSV/JSON.
Encryption
Encryption
AES-256 at rest. TLS 1.3 in transit. Key rotation handled automatically.
Access
Access controls
SSO (SAML/OIDC), MFA, IP allowlists, granular permissions per role.
AI safety
AI safety
No training on customer data. PHI redacted from model logs. Human-in-loop for sensitive actions.
Human in the loop
You decide how much Mana does on its own.
Every capability has an autonomy setting — from "draft for my approval" to "act and report". Sensitive actions always wait for a human, and every action lands in an immutable, exportable audit trail.
mana / autonomy · per capability
Billing & collectionsAct & report
Claims managementAct & report
Patient communicationApprove first
Fee changes & refundsHuman only