Security
Protecting patient health data with confidence
We have fortified PT AI Note Helper with layered technical and organisational safeguards. For security questions, contact security@intellyverse.com.
Protecting patient health data with confidence
At PT AI Note Helper, robust security measures create the strong immune system we know is vital to your clinical documentation. We know medical information is sensitive, and we have fortified the Service with layered safeguards to protect your drafts, your workspace, and any data you submit to us.
No-PHI Operating Posture
The Service is designed as a no-PHI drafting tool. The drafting interface, AI prompts, and default retention are all configured to discourage and prevent the submission of protected health information.
- Server-side redaction is applied to AI prompts to remove or reduce sensitive identifiers before they are sent to model providers.
- Upstream OpenRouter privacy and safety controls, including request-level zero-data-retention routing preferences and workspace guardrails, are configured as an additional safeguard.
- Audit logging records access, edits, and AI-generation events for any draft that may contain sensitive content.
- If you require PHI-enabled processing, a signed Business Associate Agreement (BAA) is available on request. Contact compliance@intellyverse.com to begin a BAA request.
Confidentiality
Our encryption protocols ensure your data remains confidential and readable only by authorized parties. All communication between our systems is encrypted using HTTPS/TLS (TLS 1.2 or higher). All data at rest is encrypted using AES-256 or better.
It Starts with Consent
The first step of every practitioner session is gathering consent. This ensures that patients have consented to be recorded, where applicable. The Service is designed to support practitioner-led workflows so that you remain in control of the consent, notice, and authorisation requirements that apply to your practice.
Global Compliance
Engagements with third-party vendors are governed by master service agreements ensuring adherence to HIPAA, the EU and UK GDPR, the U.S. Privacy Act and state privacy laws, and other applicable privacy obligations. We align our practices with industry frameworks including the NIST Cybersecurity Framework and ISO 27001-style controls.
Industry-Best Encryption
PT AI Note Helper uses a combination of proprietary models and certified partners for transcription and AI services. Any partner that we use must meet stringent security, privacy, and governance requirements, including a requirement that they do not store any data or use any data that we send them for the training of future models.
- Encryption in transit: HTTPS/TLS (TLS 1.2 or higher) secures all data transmissions between client devices and our infrastructure, with TLS termination and threat detection provided at the edge by Cloudflare.
- Encryption at rest: AES-256 or better is used to encrypt data before it is written to disk, safeguarding data at rest in our database and storage layers.
- Field-level encryption: Sensitive fields, including API keys, are encrypted at the application layer before persistence, using managed key material.
Key Management
Encryption keys are managed using managed key-management services, providing a secure and organised method for handling cryptographic material for field-level encryption. Key material is never exposed outside the key-management service, ensuring encryption operations are performed in a secure environment. Keys are regularly rotated in accordance with industry best practices.
No Model Training on Your Data
We believe in boundaries. The partners we work with do not store or misuse your data for training future models. It is like lending someone a book, but they cannot keep it or make copies.
Subprocessors
We rely on a small set of carefully selected subprocessors to operate the Service. As of the effective date of this page, our primary subprocessor categories are:
- Vercel: website and application hosting.
- Cloudflare Workers: edge and API execution, with TLS termination and threat detection.
- Supabase: database, authentication, and storage infrastructure.
- Stripe: payment processing for subscriptions and billing.
- OpenRouter: AI routing and model access, configured with zero-data-retention preferences and workspace guardrails.
Data Retention
Our system purges older data in accordance with your account retention settings. Drafts are retained for the period shown in your account (by default 30 days, configurable by you). After the retention period, drafts are securely deleted. Practitioners also have the option to manually delete at any time.
Access Control
Access to draft data is like VIP access at a club: access is restricted to administrators, actions are logged, and cloud-based intrusion and anomaly detection is in place (Cloud SIEM). Individual access is secured by multi-factor authentication and OpenID Connect-based authentication tokens.
Two-Person Rule for Sensitive Changes
Major changes in our system require two authorised persons to approve, ensuring a higher level of scrutiny and security. It is teamwork with a security twist.
Continuous Monitoring
Access to data is logged with audit trails, and cloud-based intrusion detection is in place to bolster security. Automated alerting and regular operational log reviews are carried out as part of the monitoring process. Our system is like a security guard that never sleeps, continuously monitoring, detecting, and preventing any suspicious activities.
Responsible Disclosure
We have a designated mailbox for your security concerns, helping us to continuously improve. If you spot a vulnerability, please email security@intellyverse.com. We will acknowledge your report within two business days and work with you to investigate and remediate the issue.
Contact
For security concerns or to report a vulnerability, contact security@intellyverse.com. For privacy questions, contact privacy@intellyverse.com. To request a BAA, contact compliance@intellyverse.com.
Intellyverse LLC, 2814 SW 6th St, Gainesville, FL 32601, USA.