Skip to content
Security and privacy

Careful with patient
information by default.

Clinic records deserve more than a promise on a marketing page. Below is how the platform is actually built, followed by an honest note on what we have not done yet.

Canadian region by default

The platform is built to deploy into AWS Canada Central. Our infrastructure definition refuses to synthesize against any other primary region.

Encrypted at rest and in transit

The database, queues, and file storage are encrypted with a customer-managed AWS KMS key with rotation enabled. Storage buckets block public access and require TLS.

Private networking

The database runs in isolated subnets with no public access. Application code runs in the same private network and reaches the database through a locked-down security group.

Managed authentication

Sign-in runs on Amazon Cognito with a strong password policy, 15-minute access tokens, token revocation, advanced security enforced, and optional TOTP multi-factor.

Organization-scoped access

Every request carries an organization and a role. Clinic admins, location admins, and receptionists get different permissions, and operational views such as appointments and tasks are further limited to a user's assigned locations.

Audit events

Sensitive actions write an audit record with the actor, organization, action, target, and outcome. That includes message sends, exports, AI reviews, support access grants, and recording deletion.

Call audio deleted after 30 days

Each recording is stamped with a deletion date when it arrives. A daily job removes the audio and marks the record, and storage lifecycle rules expire anything left behind.

AI drafts, never AI decisions

Call summaries and suggested follow-ups are stored as drafts. They only become real tasks when a person reviews and approves them, and that review is audited.

Consent checked at send time

Opt-outs from STOP replies, unsubscribe links, bounces, and complaints all write to a suppression list, which is re-checked immediately before any message leaves the platform.

No patient data in billing

Stripe receives your organization identifier and billing email. Patient and lead information is never sent to our payment processor.

Verified provider webhooks

Inbound webhooks from Twilio and Stripe are signature-verified before we act on them, and repeated deliveries are handled without double-processing.

Backups and log retention

Database backups are retained automatically, and application logs go to an encrypted log group with a defined retention window.

Where we are today

What we will not claim

Plenty of software in this category implies certifications it does not hold. Here is the current state of ours, in plain language.

  • We hold no SOC 2, HIPAA, or PHIPA certification, and we will not imply otherwise. The controls above describe how the platform is built, not a third-party attestation.
  • An independent penetration test and a completed privacy impact assessment are on our pre-launch checklist and are not finished yet.
  • Voice and SMS are delivered through Twilio, which may process message and call metadata outside Canada.
  • Avvicena is in its pilot stage. Talk to us before putting any clinical record or sensitive health information into it.
Questions about your data

Ask us anything before you migrate.

If your clinic has a privacy officer or a review process, bring them in early. We would rather answer hard questions now than surprise you later.