← nexmin

SECURITY · INFRASTRUCTURE · COMPLIANCE

your clinical material, treated as sacred.

nexmin is a copilot that listens with you. To reduce the risks of that listening, the entire architecture starts from the sovereignty of the therapist and the consultant over their data.

What follows are the technical decisions that uphold that promise.

DATA · WHERE IT LIVES

1. primary infrastructure within the european union.

Clinical data at rest stays in the European Union: the application server and the encrypted database with customer-managed keys live in Madrid. Queues and Gemini inference also remain within the EU; transcription uses an external provider under a specific transfer regime.

  • Application server in europe-southwest1 (Madrid)
  • Encrypted database in europe-southwest1 (Madrid), with customer-managed keys (CMEK)
  • Enterprise-grade DPA signed with Google Cloud
  • Clinical data at rest in the EU; external transcription is covered by its DPA and transfer safeguards

ENCRYPTION · ALL LEVELS

2. whatever gets written, gets written encrypted.

Encryption in transit (TLS 1.3) is taken for granted across the industry. nexmin adds a second layer of encryption inside the database itself, over the fields that may hold clinical material: audio, transcripts, notes, summaries, acoustic signals, hypotheses.

If one day an attacker reached the database, they would find unreadable text. And the encryption key lives separately from the storage, not alongside the data.

  • TLS 1.3 on every connection
  • Column-level encryption (Fernet, AES-128-CBC + HMAC) over fields that may hold clinical material
  • Encryption keys stored separately and rotatable
  • Audio segregated in a bucket distinct from the main database

TRAINING · NOT USED FOR TRAINING

3. your material trains no one.

The AI that listens to your sessions is Gemini, on Google Cloud Vertex AI, contracted under the enterprise no-training tier. Neither the audio, nor the transcript, nor the clinical drafts are used to train public models. Neither Google’s. Nor ours.

Vertex AI processing is ephemeral: it reads and writes the draft without using it to train models. External transcription follows the safeguards described in its DPA.

  • Vertex AI with explicit no-training flag
  • Ephemeral processing, no retention by the provider
  • Contractually binding DPA with Google Cloud
  • Your material is excluded from base-model training under the contracted mode

ACCESS · TWO-FACTOR

4. getting into your practice takes more than a password.

nexmin supports standard two-factor authentication (TOTP), compatible with any authenticator app you already have installed — Google Authenticator, 1Password, Authy, Microsoft Authenticator.

The organization admin turns it on for themselves; each therapist enables it whenever they want from their profile. A sound habit, especially after an incident with your previous provider.

  • Standard TOTP 2FA (RFC 6238)
  • Secret encrypted at rest, decrypted only at the moment of verification
  • Rate-limiting against brute-force attempts
  • Compatible with any TOTP authenticator app

TRUST LOOP · YOUR SIGNATURE OVER EVERYTHING THE AI PROPOSES

5. no draft becomes the approved version without your approval.

This is the central doctrinal decision of nexmin: the AI proposes, you decide. Every draft generated by the officers — Scriba synthesis, process variables, voice analysis, Pensa, first-session extraction — reaches your screen as an editable proposal and may remain pending review. Until you approve, nothing becomes the canonical version in the consultant’s record.

And if you later unlock a closed note to review it, everything becomes editable again. Your human signature is always the canonical version.

  • Every AI output passes through in-line validation before cementing
  • Granular edit of each field before approving
  • Closed notes can be reopened to correct
  • The human version is the canonical one for everything downstream

TRACEABILITY · WHO ACCESSED WHAT

6. auditable access on request.

Every access to clinical information is recorded in immutable logs. If at any point you need to know who consulted what and when — because the consultant requested it, an incident, or an external audit — we provide the extract.

  • Immutable logs of every access to clinical information
  • Every AI call is recorded internally with its cost and responsible party
  • Access extract available on request

RETENTION · YOU DECIDE HOW MUCH TO KEEP

7. three modes. you pick the one that respects your ethical frame.

nexmin does not decide for you. The audio retention policy is configured per organization or per individual consultant, depending on the context.

  • Ghost mode — the session is not recorded; after the session you record a brief summary audio, nexmin works on that, nothing of the audio remains
  • Standard mode — the session is recorded so the AI can listen, after the analysis the audio is deleted, the note remains
  • Retention mode — the session is recorded, analysed, and the audio is kept in case you later need to review a moment, re-analyse with a new protocol, or attend to a request

COMPLIANCE · EUROPEAN LAW AS THE BASELINE

8. gdpr, lopdgdd, spanish patient autonomy act, eu ai act.

nexmin was born in Europe, with European regulation as the baseline of the architecture, not a checkbox at the end. The platform includes safeguards and compliance documentation, while your professional framework and applicable obligations still require your own review. It also includes an informed-consent template for AI recording, available as a starting point to adapt and review before giving it to the consultant.

  • GDPR + Spanish LOPDGDD compliance
  • Spanish Patient Autonomy Act (Ley 41/2002 — patient autonomy and clinical documentation)
  • EU AI Act (Regulation 2024/1689) — applicable to AI in healthcare
  • Informed consent template for AI recording, integrated in the platform
  • DPA signable on request
  • Right to full data export at any time

NEED ANYTHING ELSE?

if you have questions about any technical point, write to us.

To request the signed DPA or go deeper into any specific architectural detail, write to hola@nexmin.ai.

The complete privacy policy, with the legal detail of data processing, lives at /privacidad.