How we protect patient information.
The essentials at a glance, then every control in detail. Each one is live in the production service, not a plan.
Encryption at rest
Patient information is encrypted field by field inside the application, on top of AES-256 storage encryption, with managed keys rotated on a documented schedule.
Encryption in transit
TLS 1.2 or higher everywhere, with HTTPS enforced and verified database connections.
Network
The systems that hold patient information are closed to the public internet and reachable only from inside a private network.
Authentication
Two-factor sign-in on every account, no exceptions. Remembered devices expire after 30 days, sessions are capped at 12 hours and can be revoked everywhere at once.
Authorization
Every request must be signed in unless it is on a short written public list, checked by automated tests. Each practice sees only its own data, and patients who open a link see only their own page.
Audit trail
Every request is logged with who, what and the outcome, kept for ten years and watched by automated alerts. A written review runs weekly.
Record integrity
Every saved note carries a tamper-evident stamp, so a change made outside the application is detected. Deleted records are held for 30 days, then purged, with each step audited.
AI processing
Your data is never used to train models, identified or de-identified. Only what the finished document needs is sent for drafting.
No trackers
No analytics, advertising, crash-reporting or telemetry library runs in the clinical apps. Fonts are self-hosted, so no third party sees a request from a page showing patient information.
Retention
Recordings stay on the recording device for at most 7 days. On the server, audio is used only to write the note and is deleted once the note is done; if processing fails, it is held encrypted for up to 7 days so the note can be retried. Deleted records are purged after 30 days. Clinical notes are kept for 10 years. A practice can ask for the return of all its data at any time.
Backups and recovery
Redundant backups with point-in-time restore, plus an independent encrypted off-site copy verified weekly. Restore drills are performed and recorded, and recovery objectives are written down.
Hosting
United States data centers only. Uptime alerts notify the Security Officer if the service becomes unavailable.
In progress
BlackOps does not yet hold a third-party attestation. The controls above are self-assessed against the HIPAA Security Rule with an evidence pointer for each, and SOC 2 readiness work began in September 2026. This page will be updated when an independent report is available.
Every change runs the test suite, secret and patient-data scans and static security analysis before it can be deployed, and every deploy is verified end to end against the live service.
| Provider | Purpose | Patient information |
|---|---|---|
| Our US cloud provider | Hosting, database, AI processing, email delivery, logging, backups | Yes, encrypted |
| Our source-code host | Code and automated testing | No; enforced by scans |
| Our website host | This marketing website only | No |
No other party receives patient information. There is no advertising and no data licensing. The named providers are listed in our security packet, available on request.
If you believe you have found a security issue, tell us before anyone else. We read every report, acknowledge within 3 business days, and fix confirmed critical issues within 7 days and high-severity issues within 30.
Security documentation is available to customers and prospective customers on request, and we answer security questionnaires. This marketing website is separate from the clinical application and holds no patient information.
This page describes controls; it is not a legal agreement.