Trust is not a feeling. It is a property you can inspect.
Not whether we take security seriously, but what we do, and what we never keep.
The safest audio file is the one that never exists.
Most clinical AI records the session and keeps the file. We do not. Speech is transcribed in memory, the words carry forward into the record, and the recording is dropped where it was made.
Nothing to breach
A store of session recordings is the worst thing this product could hold. We chose not to build one.
Consent before the microphone
Capture is opt-in per patient. Turn it off and everything else still works.
The same rule in the journal app
Speech becomes text you can edit. The audio is not retained.
The clinician knows the patient. Our systems hold a code.
Identifiers are removed on the way in, including inside free text, where they usually survive.
The filter runs before storage, not after. In our database a patient is a code, and the identity behind it stays encrypted.
Four layers around one record.
Four controls, each assuming the one outside it has already failed.
- 1NetworkTLS in transit, private cloud isolation
- 2StorageEncrypted at rest, encrypted backups
- 3IdentityPatients held as encrypted identities
- 4AccessScoped roles, every read logged
The other kind of safety: a clinician decides.
Empaithy highlights patterns for review. It does not diagnose or predict a crisis, and nothing enters the chart without a person approving it.
Who else touches it.
Third-party AI and infrastructure providers help run the service, and data may be processed outside your country. The list is current, and you are told before it changes.
The signed register, with each vendor named, goes out with the security overview.
The paperwork, available on request.
HIPAA-ready with a BAA, GDPR-aligned with a DPA, SOC 2 Type II in progress. Security reviews welcome.

Bring your security team.
Better to answer the hard questions now than during procurement.