Security overview
Encryption, MFA, audit log, tenant isolation.
ReadTrust center
We treat trust the way we treat clinical evidence: cited, verifiable, and re-validated on every release.
Encryption, MFA, audit log, tenant isolation.
Read§164.308 / .310 / .312 controls + BAA on every covered subprocessor.
ReadGDPR + CCPA + general. What we collect, why.
ReadAcceptable use, liability, termination.
ReadEssential only. No third-party tracking.
ReadStandard DPA covering EU/UK transfers.
ReadHIPAA §164.504(e) compliant BAA.
ReadUptime targets and credits per tier.
ReadWhat you can and cannot do on the platform.
ReadEvery covered subprocessor + BAA status.
ReadWCAG 2.1 AA target. Active program.
ReadEU data subject rights under Articles 15-22.
ReadCalifornia consumer privacy disclosures.
ReadUptime and incident history.
ReadSecurity researcher program + safe harbor.
ReadHow to report a security or privacy incident.
ReadTwilio A2P 10DLC + TCPA disclosures. Opt-in, frequency, STOP/HELP.
Read42 CFR §483.80(a)(4) + CDC Core Elements + Loeb / McGeer references.
ReadHow label-grounded DDIs are sourced, pulled, and verified. Educational reference, not CDS.
ReadHow the in-app Help drawer + page-context AI work, what they do not do, how queries are audited without storing raw text.
Read