Built for a healthcare procurement review.
Everything a clinic security team or procurement officer needs to start a review, in one place.
Compliance & certifications
Where we are today, stated plainly, including the one audit still in progress.
HIPAA
BAA signedHIPAA-ready, with a Business Associate Agreement signed before any pilot touches patient data.
GDPR
CompliantAccess, rectification, erasure, and portability supported end to end, with a DPA for EU controllers.
DPDP Act (India)
CompliantConsent, purpose limitation, and India data residency for Indian locations.
PIPEDA (Canada)
CompliantConsent, access, and retention controls for Canadian locations.
SOC 2 Type II
In progressAudit in progress. We operate to SOC 2 controls today and share reports under NDA as they're issued.
How we protect your data
The controls a security review looks for, with the specifics behind each one.
Encryption in transit & at rest
TLS 1.3 in transit and AES-256 at rest. Keys live in a dedicated KMS with rotation, and you can supply your own.
Role-based access & authentication
Least-privilege, role-based access with SSO/SAML and mandatory MFA for staff. Enterprise tenants can enforce SSO-only.
Audit logging
Every call, decision, and system write is logged with who, what, and when. Logs are tamper-evident and exportable.
Data retention & deletion
Retention is configurable per data type. Request a full export or deletion at any time; deletion reaches backups on their rotation.
Data residency
Pin each location's data to the US, the EU, or India. Residency is enforced at the infrastructure layer.
Recording & transcript controls
Consent notices where required, caller opt-out, and access-controlled recordings and transcripts that expire per your policy.
Tenant & data isolation
Each practice runs in a logically isolated tenant with its own keys and access boundaries.
Incident response
A 24/7 incident-response process with a defined severity model. Affected practices are notified within the timeline set in your BAA.
Availability & backups
A 99.9% availability target, daily encrypted backups, and quarterly disaster-recovery tests with documented RTO and RPO.
Security testing
Independent penetration testing every year, with a summary available under NDA.
People & training
Background checks and HIPAA training for every team member with access to customer data.
Vulnerability disclosure
Found an issue? Report it to our security team and we'll acknowledge it promptly.
security@meetveda.com
Your patient data is never used to train models.
Calls, transcripts, and records stay within your tenant and your chosen region. We don't use them for model training, and the AI providers that process a call are contractually barred from retaining it or training on it.
Security questions, answered
The questions a DPO or security team raises first, answered before the questionnaire.
Starting a review?
Get our architecture overview, subprocessor list, DPA and BAA templates, and standard questionnaire responses.
See Veda handle your exact call flows
Book a 30-minute demo. We'll model your real call volume, your PMS, and your rules, and show you the numbers you'd recover.