Security & compliance

Boring where it counts. Specific where it matters.

HIPAA has no certification programme, so we will not show you a badge. Here are the specifics your compliance reviewer will actually ask about.

HIPAA-ready BAA available TLS 1.3 + AES-256 US-based servers 99.9% uptime SLA

HIPAA-ready by design

PHI is handled under a signed Business Associate Agreement, with least-privilege access and documented data flows from the first call.

Encrypted end to end

TLS 1.3 for everything in transit and AES-256 for everything at rest. Keys are rotated and managed separately from application access.

US-based infrastructure

All processing and storage stays inside US regions. No offshore call centres and no offshore data processing.

Zero-retention option

Choose how long recordings and transcripts live — down to discarding audio the moment the call ends and keeping only the structured outcome.

Role-based access control

Granular permissions per staff member, with SSO available and every permission change written to the audit log.

Complete audit trail

Every call, transcript, chart write, and configuration change is logged and exportable for your compliance reviews.

99.9% uptime SLA

Redundant regions with automatic failover, plus a fallback route to your existing phone system if anything degrades.

Human escalation, always

Any caller can reach a person at any point. Emergency language triggers an immediate live transfer, never a hold queue.

An abstract representation of layered data protection

Straight answers

The three questions worth asking any vendor.

Is our data used to train AI models?

No. Your patient data is never used to train shared or third-party models. It serves your practice and nothing else, and that commitment is in the contract rather than in a sales email.

How long is data retained, and can we change it?

You choose. Retention is configurable down to a zero-retention mode where audio is discarded at the end of the call and only the structured outcome written to the chart is kept.

Who internally can access our recordings?

Named roles under least-privilege access, with every access event written to an audit log you can request at any time. No offshore personnel have access.

What we do not claim

Being straight about our posture.

Overstating compliance is common in this category. We would rather you trusted the parts we can prove.

What we can evidence today

  • A signed Business Associate Agreement before any patient call
  • TLS 1.3 in transit and AES-256 at rest, with managed key rotation
  • US-only processing and storage, with no offshore access
  • Role-based access control with SSO available
  • Complete, exportable audit trails
  • Configurable retention including a zero-retention mode
  • Redundant regions with automatic failover and a fallback to your phone system

What we will not pretend

We are not "HIPAA certified." Nobody is. HHS runs no certification programme, so any vendor claiming the badge is either careless or hoping you will not check. Ask us for the BAA and the security documentation instead.

Our SOC 2 Type II is in progress. Our controls are built to those criteria and we will share our current posture and documentation under NDA. We will tell you exactly where we are rather than imply a finished audit.

Compliance is shared. Your Notice of Privacy Practices, your state's call-recording consent rules, and your own risk analysis stay yours. We will help you with all three, but we cannot own them.

Security FAQ

Compliance questions in full.

Is Vocryn HIPAA compliant?
We are built for HIPAA from the ground up and we sign a Business Associate Agreement with every clinic. HIPAA has no certifying body, so treat any vendor claiming to be "HIPAA certified" with suspicion — ask for their BAA and their security documentation instead. We are happy to provide both.
Where is our patient data stored?
In US-based data centres only. Nothing is processed or stored outside the United States, and no offshore staff have access to it.
Are calls recorded, and can we turn that off?
Recording is on by default because practices find the transcripts valuable for quality review. You can shorten retention or switch to a zero-retention mode where audio is discarded at the end of the call and only the structured outcome is kept.
Do you train AI models on our patient data?
No. Your patient data is never used to train shared or third-party models. It is used to serve your practice and nothing else.
Are you SOC 2 certified?
Our controls are built to SOC 2 Type II criteria and we can share our current security documentation and posture under NDA. We will tell you plainly where we are in that process rather than overstate it.

Need our security package for a review?

We will send the BAA template, data-flow documentation, and our current security posture — usually the same working day.

Live in 10 business days

Your next patient is calling right now.

See Casey answer, book, and document a real call in a 20-minute demo — using your scheduling rules, not a canned script.

Book a Demo ROI