Trust is not a feeling. It is a property you can inspect.

Not whether we take security seriously, but what we do, and what we never keep.

Audio never storedDe-identified by defaultEncrypted in transit and at rest
The recording

The safest audio file is the one that never exists.

Most clinical AI records the session and keeps the file. We do not. Speech is transcribed in memory, the words carry forward into the record, and the recording is dropped where it was made.

VOICEtranscribeIN MEMORYTEXT · KEPTsleeping better, stillanxious about workRECORDAUDIO · DISCARDEDnever written to diskno session archive to hold or hand over

Nothing to breach

A store of session recordings is the worst thing this product could hold. We chose not to build one.

Consent before the microphone

Capture is opt-in per patient. Turn it off and everything else still works.

The same rule in the journal app

Speech becomes text you can edit. The audio is not retained.

Identity

The clinician knows the patient. Our systems hold a code.

Identifiers are removed on the way in, including inside free text, where they usually survive.

In the consulting roomthe clinician sees their patient
In our systemsthe record holds a code
NameAanya Rao
Namept_8f2a41c9
Date of birth12 March 1991
Date of birthage band 30 to 39
Contactaanya.r@mail.com · +91 98•••
Contactremoved
AddressIndiranagar, Bengaluru
Addressregion only
Session textthe merger at Acme has me up at 3am
Session textthe merger at [ORG] has me up at 3am

The filter runs before storage, not after. In our database a patient is a code, and the identity behind it stays encrypted.

Defence in depth

Four layers around one record.

Four controls, each assuming the one outside it has already failed.

1234ONE RECORD
  1. 1NetworkTLS in transit, private cloud isolation
  2. 2StorageEncrypted at rest, encrypted backups
  3. 3IdentityPatients held as encrypted identities
  4. 4AccessScoped roles, every read logged
We hold ourselves to
  • We do not keep the recording
  • Identifiers are stripped before storage
  • A patient is a code in our database
  • Model improvement uses de-identified data only
  • Patient data is never sold
  • No advertising trackers in the app
  • Nothing enters the record unreviewed
Clinical safety

The other kind of safety: a clinician decides.

Empaithy highlights patterns for review. It does not diagnose or predict a crisis, and nothing enters the chart without a person approving it.

Who else touches the data

Who else touches it.

Third-party AI and infrastructure providers help run the service, and data may be processed outside your country. The list is current, and you are told before it changes.

Cloud hosting and storageEncrypted clinical recordsConfirmed per engagement
Transactional emailAccount email addresses onlyConfirmed per engagement
Error and uptime monitoringNo clinical contentConfirmed per engagement

The signed register, with each vendor named, goes out with the security overview.

Governance

The paperwork, available on request.

HIPAA-ready with a BAA, GDPR-aligned with a DPA, SOC 2 Type II in progress. Security reviews welcome.

HIPAA · BAA availableSOC 2 Type II in progressGDPR · DPAAudit logs

Bring your security team.

Better to answer the hard questions now than during procurement.