Intelligent Clinic Management Platform
Security and privacy

Your clinic's data is protected at the architectural level

Privacy here is not a feature but the foundation: isolation between clinics, encryption, auditing, daily backups and strict control over who processes medical information, and how.

Clinic isolation

Each clinic's data resides in an isolated dataset, accessible strictly by token. Every request is scoped to your clinic alone, and the isolation is verified continuously by automated checks.

Encryption

Data in transit travels over TLS. Sensitive fields (names, contacts, clinical notes) are encrypted in the database. A clinic's integration credentials are stored encrypted.

Hosting

The infrastructure runs in Microsoft's certified cloud. Data is hosted in the Israel region, on an enterprise-grade platform with its own data-center certifications.

Access and audit

Sign-in by personal staff PIN codes with role-based permissions. Key actions are written to a secured audit log with an integrity chain.

Backups and your rights

A daily encrypted backup. At any time, the clinic can export its entire database (Excel / ZIP) and request the permanent erasure of all data.

Calls are not recorded

The voice assistant stores neither audio nor transcripts of conversations — the system keeps call metadata (number, time, duration) and whatever the assistant files at the patient's request, such as a message for the physician or a refill request.

Voice processing and your data

The platform runs two voice assistants — an in-app one (for the physician) and a telephone one (for patients). Speech recognition and synthesis run on an enterprise-grade speech platform, and telephony on a licensed global carrier.

Under our agreements, voice and text data passes through transiently, is not stored by the provider and is never used to train models (zero-data-retention terms). Written confirmation is provided on request; the current provider list is on the Sub-processors page.

Speech · zero data retentionTelephony · licensed carrierNo training on your data

Sub-processors

Medical information is not disclosed to third parties, other than to trusted infrastructure providers — each under its own Data Processing Agreement (DPA) or Business Associate Agreement (BAA):

Cloud hostingSpeech synthesis/recognitionTelephonyWhatsApp delivery

Every provider is listed by name on the Sub-processors page, and that list is kept current.

Compliance and status

The platform is a productivity tool, not a medical device. It makes no diagnoses and takes no clinical decisions: the final decision always rests with the physician, and it is the physician's note that is the record of truth.

The architecture follows a "privacy first" principle and is aligned with the requirements of GDPR and with the HIPAA approach. The full legal documents — Privacy Policy, Terms of Service and EULA — are available on the website.

Documents on request

On written request we provide clinics and their IT departments with the BAA (HIPAA), the Data Processing Agreement DPA (GDPR) and the speech provider's confirmation of non-retention.

Request documents →