Security and privacy
What is in place, and what is not.
Most vendor security pages list only strengths. This one lists both, because a reviewer is going to find the gaps anyway and would rather hear them from us.
Last reviewed: September 20, 2026.
In place today
Not in place yet
If any of these is a requirement for your organization, tell us during the review rather than after. We will say plainly whether we can meet it and by when.
Handling
How information moves through the product.
Where it is hosted
Our primary hosting provider is Google Cloud Platform, in the United States. Company email, calendar, and documents sit in Google Workspace under the signed HIPAA amendment.
How AI processing works
Content is processed by third-party AI providers under contract. They are prohibited from using it to train their own models. We do not use your health information to train general-purpose AI models.
When we are a business associate
Where we handle protected health information for a hospital, clinic, health system, or research institution, we act as that organization’s business associate under a written agreement executed before any data is shared.
Collection
Four things we do not collect.
Security questions usually focus on how well data is protected. The stronger answer is often that the data was never collected.
Running a vendor review?
Send us the questionnaire. We answer it as written, including the questions where the answer is no.