Security and privacy

What is in place, and what is not.

Most vendor security pages list only strengths. This one lists both, because a reviewer is going to find the gaps anyway and would rather hear them from us.

Last reviewed: September 20, 2026.

In place today

Encryption in transit and at restData is encrypted on the wire and in storage.
Least-privilege accessAccess is granted to the smallest set of people and services that need it, and reviewed rather than assumed.
Access loggingAdministrative actions are logged and the logs are retained.
Signed HIPAA Business Associate Amendment with GoogleExecuted September 20, 2026 for the Google Workspace environment, alongside the Cloud Data Processing Addendum.
Services restricted to those the agreement coversGoogle services outside the covered list are switched off for the organization, and third-party applications cannot reach company mail, files, calendar, or contacts without explicit administrator approval.
Records are not used to train general AI modelsOur AI processing providers handle content under contract and are prohibited from training their own models on it.

Not in place yet

No third-party penetration testWe have not commissioned one. We do not claim testing we have not done.
No multi-factor authentication on the study applicationAdministrative access uses individually identified accounts with enforced password strength, not a second factor. Google Workspace accounts are managed separately.
No SOC 2 Type II reportNot audited, not in progress as of this review date.
No HITRUST certificationNot held.
No formal data loss prevention or legal holdOur current Google Workspace tier does not include Vault or DLP tooling.
No 24/7 security operations centreWe are a small company and we staff accordingly.

If any of these is a requirement for your organization, tell us during the review rather than after. We will say plainly whether we can meet it and by when.

Handling

How information moves through the product.

Where it is hosted

Our primary hosting provider is Google Cloud Platform, in the United States. Company email, calendar, and documents sit in Google Workspace under the signed HIPAA amendment.

How AI processing works

Content is processed by third-party AI providers under contract. They are prohibited from using it to train their own models. We do not use your health information to train general-purpose AI models.

When we are a business associate

Where we handle protected health information for a hospital, clinic, health system, or research institution, we act as that organization’s business associate under a written agreement executed before any data is shared.

Collection

Four things we do not collect.

Security questions usually focus on how well data is protected. The stronger answer is often that the data was never collected.

CameraNo camera access is requested or used.
MicrophoneNo audio capture of any kind.
LocationNo GPS or precise location data.
Payment detailsNo card data is collected or processed through the product.

Running a vendor review?

Send us the questionnaire. We answer it as written, including the questions where the answer is no.