Skip to main content

Trust center

Compliance, shipped in code.

We treat trust the way we treat clinical evidence: cited, verifiable, and re-validated on every release.

Security overview

Encryption, MFA, audit log, tenant isolation.

Read

HIPAA

§164.308 / .310 / .312 controls + BAA on every covered subprocessor.

Read

Privacy policy

GDPR + CCPA + general. What we collect, why.

Read

Terms of Service

Acceptable use, liability, termination.

Read

Cookie policy

Essential only. No third-party tracking.

Read

Data Processing Agreement

Standard DPA covering EU/UK transfers.

Read

Business Associate Agreement

HIPAA §164.504(e) compliant BAA.

Read

Service Level Agreement

Uptime targets and credits per tier.

Read

Acceptable Use Policy

What you can and cannot do on the platform.

Read

Subprocessors

Every covered subprocessor + BAA status.

Read

Accessibility statement

WCAG 2.1 AA target. Active program.

Read

GDPR rights

EU data subject rights under Articles 15-22.

Read

CCPA rights

California consumer privacy disclosures.

Read

Status page

Uptime and incident history.

Read

Responsible disclosure

Security researcher program + safe harbor.

Read

Incident reporting

How to report a security or privacy incident.

Read

SMS terms & opt-in

Twilio A2P 10DLC + TCPA disclosures. Opt-in, frequency, STOP/HELP.

Read

Antibiotic Stewardship methodology

42 CFR §483.80(a)(4) + CDC Core Elements + Loeb / McGeer references.

Read

Drug interactions — methodology

How label-grounded DDIs are sourced, pulled, and verified. Educational reference, not CDS.

Read

In-app Help AI methodology

How the in-app Help drawer + page-context AI work, what they do not do, how queries are audited without storing raw text.

Read