Security & Compliance
Built for healthcare from the ground up
You are trusting us with your residents’ and families’ most sensitive information. We treat that the way a healthcare organization has to — with real safeguards, a real paper trail, and a signed agreement in place before a single call is handled.
Customer PHI remains blocked until the Business Associate Agreement and technical readiness approval are both in place.
The customer BAA is executed during onboarding, and the technical gate stays closed until every required data service is approved for the intended PHI path. You receive the executed agreement and the applicable vendor list for your records. A signed customer BAA by itself does not open the PHI gate.
How we protect the information
Not a marketing checkbox — the specific controls that stand between a caller’s health details and anyone who shouldn’t see them.
Application data encryption
Application API traffic uses HTTPS and stored application data uses encryption at rest. Voice-media transport and retention stay inside the pre-PHI readiness gate until provider evidence is verified.
Facility data is isolated
Database authorization policies scope facility records to the current user's verified memberships, with cross-tenant tests around the PHI paths.
Two-factor for administrators
Owner and administrator accounts must complete two-factor sign-in before privileged facility access.
Defined access events are logged
Defined high-risk reads and administrative actions generate audit events with who, what, and when. We do not claim that every possible data read is captured.
The AI knows its limits
The voice flow is designed and tested to avoid disclosing resident health information to callers or connecting outside callers directly into resident rooms. When a situation needs a person, it hands off.
Your data stays yours
You can export your data at any time, and when a relationship ends we return or securely destroy protected health information on a defined timeline.
A real program, not a promise
Documented, tested, and available for your team to review.
Behind the product is a written compliance program: a risk assessment, an incident-response and breach-notification process, a contingency and backup plan we actually test, access reviews, and a register of every vendor and their agreement.
Our systems are put through ongoing security review and testing. Before real customer PHI is enabled, the onboarding gate also requires the applicable agreements and covered-service readiness to be verified.
Your compliance or legal team is welcome to review the details. We share our security packet and executed agreements under a mutual NDA — just ask.
Have your compliance team take a look
We would rather answer the hard questions up front. Book a walk-through and bring whoever needs to sign off.