Trust
Security
What protects your practice's data, stated specifically enough that your IT advisor can evaluate it. For the HIPAA-specific obligations, see HIPAA compliance.
Infrastructure
- US-hosted infrastructure; PHI does not leave US regions
- Network isolation between customer environments
- Automated patching and dependency scanning
- Encrypted backups with tested restore procedures
Access
- Role-based access control with least-privilege defaults
- Multi-factor authentication required for all staff accounts
- Access reviews on a defined cadence, with revocation on role change
- All production access logged and attributable to an individual
Data
- TLS 1.3 in transit, AES-256 at rest
- Configurable retention for recordings, transcripts and messages
- Customer-initiated export and deletion, propagated to subprocessors
- Six-year audit log retention on access and disclosure
Operations
- Documented incident response with defined severity levels
- Breach notification procedures aligned to HIPAA timelines
- Subprocessor register available on request, each under a BAA
- SOC 2 Type II audit planned; no certification claimed until it completes
Reporting
Found a vulnerability?
Send it to support@optni.ai. We will acknowledge within one business day and keep you updated until it is resolved. We do not pursue legal action against good-faith research.