Trust is earned in the details and stated honestly.
Behavioral-health data deserves specifics, not badges. This page describes exactly how the platform protects information, what agreements we sign, and what is still in progress.
Book a workflow demoEncryption
Encryption in transit is in place today; encryption at rest, key management, and secure expiring upload links are part of the production readiness gate before any PHI.
Role-based access
Role-based permissions ship with the production readiness gate; today every workspace member has equal access and no patient data is present.
Audit logs
Every view, edit, verification, message, and escalation will be timestamped, attributable, and exportable for compliance review — part of the production readiness gate.
Retention & recovery
Configurable data-retention windows and routine backups, with recovery procedures tested and documented before any production deployment.
Vendors & subprocessors
A subprocessor list with data-flow descriptions will be maintained for production deployments, with vendor review before any new processor touches regulated data.
Incident response
An incident-response process with notification obligations that meet business-associate requirements will be documented and in place before any production deployment.
No unearned logos. Ever.
BAA
A business associate agreement is part of every production deployment that receives, stores, or transmits PHI on a provider's behalf.
42 CFR Part 2
For substance-use programs: Part 2 support will ship with consent controls, restricted redisclosure, and Part 2-aware audit history before any SUD patient data, aligned with the final rule enforced from February 2026.
SOC 2
A SOC 2 audit is part of our production readiness roadmap. We publish certification status only when an audit is complete, never before.
Penetration testing
Independent testing is part of the production readiness gate, with summaries available under NDA.
Security contact
Questions, disclosures, or a security review to run?