Security

How we protect patient information.

The essentials at a glance, then every control in detail. Each one is live in the production service, not a plan.

AES-256Encryption at rest, with patient fields encrypted a second time
TLS 1.2+Encryption in transit, on every connection
Two-factorOn every account, no exceptions
Audit trailEvery request logged and kept for ten years
US onlyData stays in United States data centers
No AI trainingYour data is never used to train AI models
01Every control, in detail
Live control

Encryption at rest

Patient information is encrypted field by field inside the application, on top of AES-256 storage encryption, with managed keys rotated on a documented schedule.

Live control

Encryption in transit

TLS 1.2 or higher everywhere, with HTTPS enforced and verified database connections.

Live control

Network

The systems that hold patient information are closed to the public internet and reachable only from inside a private network.

Live control

Authentication

Two-factor sign-in on every account, no exceptions. Remembered devices expire after 30 days, sessions are capped at 12 hours and can be revoked everywhere at once.

Live control

Authorization

Every request must be signed in unless it is on a short written public list, checked by automated tests. Each practice sees only its own data, and patients who open a link see only their own page.

Live control

Audit trail

Every request is logged with who, what and the outcome, kept for ten years and watched by automated alerts. A written review runs weekly.

Live control

Record integrity

Every saved note carries a tamper-evident stamp, so a change made outside the application is detected. Deleted records are held for 30 days, then purged, with each step audited.

Live control

AI processing

Your data is never used to train models, identified or de-identified. Only what the finished document needs is sent for drafting.

Live control

No trackers

No analytics, advertising, crash-reporting or telemetry library runs in the clinical apps. Fonts are self-hosted, so no third party sees a request from a page showing patient information.

Live control

Retention

Recordings stay on the recording device for at most 7 days. On the server, audio is used only to write the note and is deleted once the note is done; if processing fails, it is held encrypted for up to 7 days so the note can be retried. Deleted records are purged after 30 days. Clinical notes are kept for 10 years. A practice can ask for the return of all its data at any time.

Live control

Backups and recovery

Redundant backups with point-in-time restore, plus an independent encrypted off-site copy verified weekly. Restore drills are performed and recorded, and recovery objectives are written down.

Live control

Hosting

United States data centers only. Uptime alerts notify the Security Officer if the service becomes unavailable.

Independent attestation

In progress

BlackOps does not yet hold a third-party attestation. The controls above are self-assessed against the HIPAA Security Rule with an evidence pointer for each, and SOC 2 readiness work began in September 2026. This page will be updated when an independent report is available.

Every change runs the test suite, secret and patient-data scans and static security analysis before it can be deployed, and every deploy is verified end to end against the live service.

Who receives data
ProviderPurposePatient information
Our US cloud providerHosting, database, AI processing, email delivery, logging, backupsYes, encrypted
Our source-code hostCode and automated testingNo; enforced by scans
Our website hostThis marketing website onlyNo

No other party receives patient information. There is no advertising and no data licensing. The named providers are listed in our security packet, available on request.

Report a vulnerability

If you believe you have found a security issue, tell us before anyone else. We read every report, acknowledge within 3 business days, and fix confirmed critical issues within 7 days and high-severity issues within 30.

info@blackopshealth.com · security.txt

For reviewers

Security documentation is available to customers and prospective customers on request, and we answer security questionnaires. This marketing website is separate from the clinical application and holds no patient information.

This page describes controls; it is not a legal agreement.