Intelligent Clinic Management Platform
๐Ÿ”’ Security and privacy

Your clinic's data is protected โ€” at the architecture level

Privacy here isn't a feature โ€” it's the foundation: isolation between clinics, encryption, audit, daily backups, and strict control over who processes medical information and how.

๐Ÿงฉ

Clinic isolation

Each clinic's data lives in an isolated dataset, accessible strictly by token. Every request is scoped to your clinic only, and the isolation is continuously checked by automated guards.

๐Ÿ›ก๏ธ

Encryption

Data in transit travels over TLS. Sensitive fields (names, contacts, clinical notes) are encrypted in the database. A clinic's integration credentials are stored encrypted.

๐ŸŒ

Hosting

The infrastructure runs in Microsoft's certified cloud. Data is hosted in the Israel region, on a world-class platform with its own data-center certifications.

๐Ÿ‘๏ธ

Access and audit

Sign-in by personal staff PIN codes with role-based permissions. Key actions are written to a secured audit log with an integrity chain.

๐Ÿ’พ

Backups and your rights

A daily encrypted backup. At any time, the clinic can export its entire database (Excel / ZIP) and request the permanent erasure of all data.

๐ŸŽ™๏ธ

Calls are not recorded

The voice agent stores neither audio nor transcripts of conversations โ€” the system keeps call metadata (number, time, duration) and whatever the agent files at the patient's request, such as a message for the doctor or a refill request.

Artificial intelligence and your data

The platform runs two voice assistants โ€” an internal one (for the physician) and a phone one (for patients). Speech recognition and synthesis run on an enterprise-grade speech platform, and telephony on a licensed global carrier.

Under our agreements, voice and text data is passed through transiently and is not stored by the provider, nor is it used to train models (zero-data-retention terms). Written confirmation is provided on request; the current provider list is on the Sub-processors page.

Speech ยท zero data retentionTelephony ยท licensed carrierNo training on your data

Sub-processors

Medical information is not shared with third parties, except for trusted infrastructure providers โ€” each under its own Data Processing Agreement (DPA) or Business Associate Agreement (BAA):

Cloud hostingSpeech synthesis/recognitionTelephonyWhatsApp delivery

The named, always-current list of providers is published on the Sub-processors page.

Compliance and status

The platform is a productivity tool, not a medical device. It does not make diagnoses or take clinical decisions: the final decision always rests with the physician, and it is the physician's note that is the record of truth.

The architecture is built on a "privacy first" principle and is aligned with the requirements of GDPR and the HIPAA approach. The full legal documents โ€” Privacy Policy, Terms of Use, and EULA โ€” are available on the website.

Documents on request

We provide the BAA (HIPAA), the Data Processing Agreement DPA (GDPR), and the speech provider's confirmation of non-retention to clinics and their IT departments upon written request.

Request documents โ†’