Built for a healthcare procurement review.

Everything a clinic security team or procurement officer needs to start a review, in one place.

Compliance & certifications

Where we are today, stated plainly, including the one audit still in progress.

  • HIPAA

    BAA signed

    HIPAA-ready, with a Business Associate Agreement signed before any pilot touches patient data.

  • GDPR

    Compliant

    Access, rectification, erasure, and portability supported end to end, with a DPA for EU controllers.

  • DPDP Act (India)

    Compliant

    Consent, purpose limitation, and India data residency for Indian locations.

  • PIPEDA (Canada)

    Compliant

    Consent, access, and retention controls for Canadian locations.

  • SOC 2 Type II

    In progress

    Audit in progress. We operate to SOC 2 controls today and share reports under NDA as they're issued.

How we protect your data

The controls a security review looks for, with the specifics behind each one.

  • Encryption in transit & at rest

    TLS 1.3 in transit and AES-256 at rest. Keys live in a dedicated KMS with rotation, and you can supply your own.

  • Role-based access & authentication

    Least-privilege, role-based access with SSO/SAML and mandatory MFA for staff. Enterprise tenants can enforce SSO-only.

  • Audit logging

    Every call, decision, and system write is logged with who, what, and when. Logs are tamper-evident and exportable.

  • Data retention & deletion

    Retention is configurable per data type. Request a full export or deletion at any time; deletion reaches backups on their rotation.

  • Data residency

    Pin each location's data to the US, the EU, or India. Residency is enforced at the infrastructure layer.

  • Recording & transcript controls

    Consent notices where required, caller opt-out, and access-controlled recordings and transcripts that expire per your policy.

  • Tenant & data isolation

    Each practice runs in a logically isolated tenant with its own keys and access boundaries.

  • Incident response

    A 24/7 incident-response process with a defined severity model. Affected practices are notified within the timeline set in your BAA.

  • Availability & backups

    A 99.9% availability target, daily encrypted backups, and quarterly disaster-recovery tests with documented RTO and RPO.

  • Security testing

    Independent penetration testing every year, with a summary available under NDA.

  • People & training

    Background checks and HIPAA training for every team member with access to customer data.

  • Vulnerability disclosure

    Found an issue? Report it to our security team and we'll acknowledge it promptly.

    security@meetveda.com

Your patient data is never used to train models.

Calls, transcripts, and records stay within your tenant and your chosen region. We don't use them for model training, and the AI providers that process a call are contractually barred from retaining it or training on it.

Security questions, answered

The questions a DPO or security team raises first, answered before the questionnaire.

Starting a review?

Get our architecture overview, subprocessor list, DPA and BAA templates, and standard questionnaire responses.

Request pack

See Veda handle your exact call flows

Book a 30-minute demo. We'll model your real call volume, your PMS, and your rules, and show you the numbers you'd recover.

hello@meetveda.com