Trust Center

HIPAA-compliant from day one. Enterprise-grade security designed for behavioral health — so you can focus on your clients, not your compliance checklist.

HIPAASOC 2BAAEncrypted

Built for healthcare

Our platform meets the strictest compliance standards in healthcare technology.

HIPAA Compliant

Active

Full compliance with the Health Insurance Portability and Accountability Act. BAAs executed with all subprocessors.

SOC 2 Type II

In Progress

Infrastructure designed to meet SOC 2 Type II trust service criteria. Audit currently underway.

HITRUST CSF

Planned

Security controls aligned with the HITRUST Common Security Framework. Certification timeline 2027.

WCAG 2.1 AA

Accessible

Level AA conformance with Web Content Accessibility Guidelines. Tested with screen readers and keyboard navigation.

Defense in depth

Multi-layered security controls implementing the administrative, physical, and technical safeguards required by the HIPAA Security Rule.

Data Encryption

AES-256 at rest · TLS 1.3 in transit

All Protected Health Information is encrypted at every layer. PHI is never stored in plaintext, and all API communications use modern TLS 1.3 encryption.

Multi-Factor Authentication

SMS + TOTP

All provider accounts support multi-factor authentication via SMS verification codes and time-based one-time passwords (TOTP) through authenticator apps.

Role-Based Access Control

4 distinct roles

Granular permissions across Owner, Admin, Clinician, and Supervisor roles. Each role has precisely scoped access to clinical data and administrative functions.

HIPAA Audit Logging

Immutable · 6+ year retention

Every access to Protected Health Information is logged in an immutable, tamper-proof audit trail. Logs are retained for 6+ years per HIPAA requirements.

Session Monitoring

IP · Device · Browser tracking

Active session monitoring tracks IP addresses, device fingerprints, and browser metadata. Suspicious activity triggers automatic alerts and session revocation.

Break-Glass Emergency Access

HIPAA §164.312(a)(2)(ii)

Emergency access procedures compliant with HIPAA Security Rule requirements. All break-glass access is fully audited and reviewed post-incident.

Powered by Google Cloud

Enterprise infrastructure backed by Google's HIPAA-eligible cloud services with a fully executed Business Associate Agreement.

Google Cloud Platform

us-central1 region

All infrastructure runs in GCP's us-central1 region with enterprise-grade SLAs, DDoS protection, and physical security controls.

Firebase Identity Platform

Enterprise authentication

Google's Identity Platform provides secure authentication with built-in brute-force protection, account enumeration prevention, and session management.

Cloud Firestore

Encryption at rest by default

HIPAA-eligible database with automatic encryption at rest, granular security rules, and real-time data synchronization across all clients.

HIPAA BAA with Google Cloud

Executed BAA

Business Associate Agreement executed with Google Cloud covering all HIPAA-eligible services used in the TrustRoom platform.

Your identity provider, your rules

Full enterprise identity management — connect your existing IdP, automate provisioning, and enforce organization-wide security policies.

SSO (SAML 2.0 / OIDC)

Available

Self-service SSO configuration for enterprise practices. Connect your existing identity provider — Okta, Azure AD, Google Workspace, or any SAML 2.0 / OIDC compliant IdP.

SCIM 2.0 Provisioning

Available

Automated user provisioning and deprovisioning via SCIM 2.0. Sync your team directory and ensure instant access revocation when clinicians leave the practice.

MFA Enforcement

Available

Practice administrators can enforce multi-factor authentication across their entire organization. Per-user or org-wide MFA policy management.

EHR integrations

Standards-based interoperability with leading electronic health record systems. Export clinical data in any format your organization requires.

FHIR R4 API

Available

HL7 FHIR R4 compliant API for standardized clinical data exchange. Export session notes, care plans, and patient records in interoperable format.

athenahealth

Available

Direct integration with athenahealth for bi-directional clinical data exchange. Push notes, pull demographics, sync appointments.

Epic

Planned

Epic EHR integration for large health systems. Smart on FHIR app launch and clinical data interoperability.

Cerner (Oracle Health)

Planned

Oracle Cerner integration for enterprise health system deployments. FHIR-based data exchange and single sign-on.

Trusted vendors

Every vendor with access to Protected Health Information has a signed Business Associate Agreement and meets our security requirements. We provide 30 days advance notice before adding new subprocessors.

PHI Subprocessors

Business Associate Agreement in place with each vendor. These vendors may process, store, or transmit Protected Health Information.

VendorPurposeBAA
Google Cloud Platform
Cloud infrastructure, compute, storage, and database
Stripe
Payment processing and subscription management
Amazon Web Services (SES)
Transactional email delivery
Deepgram
HIPAA-compliant audio transcription
Google AI / Vertex AI
Clinical AI models and vector search

Customer-Controlled Integrations

Connected at the customer's discretion via OAuth. Data is shared only when a customer activates the corresponding integration.

ServicePurpose
Zoom
Session recording retrieval and calendar integration
Google Meet / Calendar
Session recording retrieval and calendar sync
Microsoft Teams / Outlook
Session recording retrieval and calendar sync
Apple HealthKit
Patient health data on iOS (patient-consented)
Health Connect (Google)
Patient health data on Android (patient-consented)

Infrastructure Vendors

These vendors provide infrastructure services but do not process, access, or store Protected Health Information.

VendorPurpose
Vercel
Web hosting for provider portal and marketing site
Capgo
Over-the-air updates for provider mobile app
Expo / EAS
React Native build service for patient mobile app
Resend
Secondary email delivery (Microsoft/Outlook optimization)
Postmark
Secondary email delivery (corporate inbox optimization)
GitHub
Source code repository and CI/CD pipeline

Security resources

Access our compliance documentation, request a BAA, or reach our security team for enterprise assessments.

Coming Soon

Security Whitepaper

Detailed technical security architecture documentation

Coming Soon

HECVAT

Higher Education Cloud Vendor Assessment Toolkit

Coming Soon

SIG Questionnaire

Standardized Information Gathering questionnaire

Security questions?

We're here to help.

Our security team is available to answer questionnaires, schedule assessments, and support your procurement process.