Security · Compliance
Security your compliance team can sign off on.
This was built for clinical data from the first line of code. Here's how we protect what you type, what a model sees, and what ends up in your notes. Where a claim below isn't backed by a public source yet, the ledger further down marks it pending instead of implying it.
01
PHI tokenized before it reaches a model
Identifying details are detected and tokenized before anything leaves your session. The underlying model never sees a name, a date of birth, or a chart number in the clear.
02
Encrypted end to end
Data is encrypted in transit (TLS) and at rest. Your sessions and drafts are protected the whole way, not just while they're moving.
03
HIPAA compliant, BAA included
This is built for HIPAA compliance, and a signed Business Associate Agreement is included by default on every paid plan, not sold as a separate add-on. Free trial usage isn't covered. See the BAA page for exactly where that line sits.
04
Least-privilege access
Role-based access and authentication on every session. Only you reach your patients' information.
05
Never used for training
We collect the minimum needed to help you draft. We don't sell data, and clinical content is never used to train AI models, ours or any third party's.
06
Audited infrastructure
Runs on hardened cloud infrastructure with continuous monitoring and automated backups.
07
Logging & monitoring
Access to clinical data is logged and monitored for anomalies, so nothing happens in the dark.
08
Incident response
A documented incident response plan with breach notification aligned to HIPAA timelines.
Evidence ledger
Agreements & certifications
What's contractually in place versus what's on the roadmap.
EvidenceProduct & legal (PROJECT_CONTEXT §4)
BAAs ship on paid plans, not as a separate add-on. Self-serve trial usage is not covered. See the BAA page for exactly where that line sits.
EvidenceRoadmap item
Not complete yet. We're not going to claim it until an auditor has signed off.
EvidenceRoadmap item
Same as SOC 2 Type II, tracked internally, not yet closed, not claimed here.
Evidence ledger
Access & storage
The specifics a practice's compliance officer will usually ask for directly, beyond what's covered above.
EvidenceNot yet published
The product supports multi-model access, but we haven't confirmed a public list of which model providers are in rotation, or how that choice is made per request.
EvidenceProduct (Aug 2026)
By default, session data is kept for a limited period on every plan. You can set retention to zero to disable it entirely, or choose unlimited retention on higher plans.
EvidenceNot yet published
We haven't published a kept-current list of every vendor involved in delivering the service. That's an open item, not a secret.
Evidence ledger
Open items we're not hiding
Things this site intentionally does not claim, because they aren't true yet.
EvidenceProduct roadmap (PROJECT_CONTEXT §4)
Organizations that require government-cloud isolation aren't a current fit. We'd rather say that plainly than leave it ambiguous.
EvidenceProduct roadmap (PROJECT_CONTEXT §4)
The current focus is independent practices and small groups. Deep EHR write-back is not part of that today.
