Skip to content
optniai

Trust

Security

What protects your practice's data, stated specifically enough that your IT advisor can evaluate it. For the HIPAA-specific obligations, see HIPAA compliance.

Infrastructure

  • US-hosted infrastructure; PHI does not leave US regions
  • Network isolation between customer environments
  • Automated patching and dependency scanning
  • Encrypted backups with tested restore procedures

Access

  • Role-based access control with least-privilege defaults
  • Multi-factor authentication required for all staff accounts
  • Access reviews on a defined cadence, with revocation on role change
  • All production access logged and attributable to an individual

Data

  • TLS 1.3 in transit, AES-256 at rest
  • Configurable retention for recordings, transcripts and messages
  • Customer-initiated export and deletion, propagated to subprocessors
  • Six-year audit log retention on access and disclosure

Operations

  • Documented incident response with defined severity levels
  • Breach notification procedures aligned to HIPAA timelines
  • Subprocessor register available on request, each under a BAA
  • SOC 2 Type II audit planned; no certification claimed until it completes

Reporting

Found a vulnerability?

Send it to support@optni.ai. We will acknowledge within one business day and keep you updated until it is resolved. We do not pursue legal action against good-faith research.