The compliance brief, in plain terms
Security teams ask the same handful of questions before they'll sign off. Here's what we tell them before they ask twice.
Tokenized before it thinks
Identifying details are stripped and tokenized before any request reaches a model. The model never sees the raw patient record.
A BAA that isn't a negotiation
A signed Business Associate Agreement ships on every paid plan by default, not as an enterprise upsell you have to ask for.
Encrypted in transit and at rest
Requests and stored notes are encrypted end to end. Access to your account is scoped to you and the team you invite.
Nothing trains on your patients
You control what's retained. Nothing you paste is used to train an external model, ever.
Pick your model
GPT, Claude, and other leading models sit behind one compliant layer, so you're never locked into a single vendor's judgment.
You control retention
Delete conversations and drafts from your account at any time. Nothing lingers longer than you want it to.