Built with privacy and security in mind.
We work inside practices that handle patient information. The way we handle data is part of the build, not an afterthought.
What this means in practice.
Least privilege by default
We request the narrowest access that the work requires, and read-only wherever reading is enough.
Data minimization
We work with the fields a solution actually needs. Patient information we don't need, we don't pull.
HIPAA-aligned practices
Engagements that involve protected health information are handled under HIPAA-aligned practices, with a BAA available on request.
Human oversight
Anything patient-facing or clinical stays under human review. Agents surface and draft; your team decides.
How we handle access and data.
Access
Access is requested per engagement, scoped to the systems the build touches, and read-only wherever reading is enough. Credentials are never shared between clients.
Data handling
We work with the specific fields a solution needs. Data in transit is encrypted, and we don't copy patient records into places the practice hasn't agreed to.
Protected health information
Where an engagement involves protected health information, it is handled under HIPAA-aligned practices and a Business Associate Agreement is available on request before any access begins.
Oversight
Agents surface findings and draft actions. Anything patient-facing or clinical is reviewed by your team before it goes out. We don't automate clinical judgement.
Change and offboarding
Access is reviewed as engagements change and revoked when work ends. You can ask us to remove data we hold at any time.
Security review or questionnaire?
Send it over. We'd rather answer specific questions about your environment than publish generic assurances.