Security
HIPAA-eligible infrastructure, encrypted data at rest and in transit, audit logs on every clinical action. Built with HIPAA-aware workflows for the security reviews that come with real revenue.
Encryption and storage
Audit log
Infrastructure
Eligible
Type II · planned
Available on Growth+
Data residency
Posture
At rest across the database, file storage, and backups, with AWS-managed keys.
All client and inter-service traffic uses modern TLS only.
Every clinical action recorded. PII scrubbed. Retained 13 months.
Provider, practitioner, front desk, admin. Permissions enforced server-side.
SAML and OIDC support shipping Q4 on the Enterprise tier.
TOTP and recovery codes available today. WebAuthn next.
Sub-processors
No hidden vendors. Every party that handles PHI is named here, with the role they play and BAA status shown by vendor.
| Sub-processor | Role | Region | BAA |
|---|---|---|---|
| Amazon Web Services | Database (Aurora), storage (S3), email (SES), AI (Bedrock + Transcribe) | US (us-east-2) | Executed |
| Fly.io | Application hosting and compute | US (iad) | Executed |
| Telnyx | SMS and 10DLC messaging | US | Pending |
| Stripe | Card payments and Connect payouts | US | Not required |
| Intuit QuickBooks | Accounting sync (invoices, payments) | US | Not required |
| Sentry | Error monitoring (PII scrubbed) | US | Not required |
| Upstash | Rate limiting (IPs and counters) | US | Not required |
✦ Patient data never leaves US borders by default
Executed = signed BAA. Pending = BAA in process; patient SMS goes live once it is signed. Not required = the vendor does not receive PHI.
Compliance
We respond to security questionnaires and BAA requests inside one business day. Most clinics clear review on the first pass.