Security & compliance
Boring where it counts. Specific where it matters.
HIPAA has no certification programme, so we will not show you a badge. Here are the specifics your compliance reviewer will actually ask about.
HIPAA-ready by design
PHI is handled under a signed Business Associate Agreement, with least-privilege access and documented data flows from the first call.
Encrypted end to end
TLS 1.3 for everything in transit and AES-256 for everything at rest. Keys are rotated and managed separately from application access.
US-based infrastructure
All processing and storage stays inside US regions. No offshore call centres and no offshore data processing.
Zero-retention option
Choose how long recordings and transcripts live — down to discarding audio the moment the call ends and keeping only the structured outcome.
Role-based access control
Granular permissions per staff member, with SSO available and every permission change written to the audit log.
Complete audit trail
Every call, transcript, chart write, and configuration change is logged and exportable for your compliance reviews.
99.9% uptime SLA
Redundant regions with automatic failover, plus a fallback route to your existing phone system if anything degrades.
Human escalation, always
Any caller can reach a person at any point. Emergency language triggers an immediate live transfer, never a hold queue.

Straight answers
The three questions worth asking any vendor.
Is our data used to train AI models?
No. Your patient data is never used to train shared or third-party models. It serves your practice and nothing else, and that commitment is in the contract rather than in a sales email.
How long is data retained, and can we change it?
You choose. Retention is configurable down to a zero-retention mode where audio is discarded at the end of the call and only the structured outcome written to the chart is kept.
Who internally can access our recordings?
Named roles under least-privilege access, with every access event written to an audit log you can request at any time. No offshore personnel have access.
What we do not claim
Being straight about our posture.
Overstating compliance is common in this category. We would rather you trusted the parts we can prove.
What we can evidence today
- A signed Business Associate Agreement before any patient call
- TLS 1.3 in transit and AES-256 at rest, with managed key rotation
- US-only processing and storage, with no offshore access
- Role-based access control with SSO available
- Complete, exportable audit trails
- Configurable retention including a zero-retention mode
- Redundant regions with automatic failover and a fallback to your phone system
What we will not pretend
We are not "HIPAA certified." Nobody is. HHS runs no certification programme, so any vendor claiming the badge is either careless or hoping you will not check. Ask us for the BAA and the security documentation instead.
Our SOC 2 Type II is in progress. Our controls are built to those criteria and we will share our current posture and documentation under NDA. We will tell you exactly where we are rather than imply a finished audit.
Compliance is shared. Your Notice of Privacy Practices, your state's call-recording consent rules, and your own risk analysis stay yours. We will help you with all three, but we cannot own them.
Security FAQ
Compliance questions in full.
Is Vocryn HIPAA compliant?
Where is our patient data stored?
Are calls recorded, and can we turn that off?
Do you train AI models on our patient data?
Are you SOC 2 certified?
Need our security package for a review?
We will send the BAA template, data-flow documentation, and our current security posture — usually the same working day.
