Vestibo

Security & compliance

How Vestibo protects your customers.

A HIPAA-eligible tier, a SOC 2 program in progress, and encryption controls you can attest from your account.

Encryption attestation · KMS · HIPAA-eligible tier

What we commit to

Six commitments, plain English.

Each commitment maps to a control in our SOC 2 readiness program (audit not yet completed) and to a clause in our standard BAA. Click any tile for the technical detail.

  • Encryption at rest

    Integration credentials and OAuth tokens are encrypted at the application layer with Fernet (AES-128-CBC + HMAC-SHA256), keys held outside the application image. Transcripts, audit logs, and backups are encrypted at rest by AWS storage (RDS/S3). Keys can be rotated on demand.

  • Encryption in transit

    TLS 1.2+ enforced on every public endpoint. HTTP requests redirect to HTTPS at the edge; HSTS is on.

  • Cloud KMS

    AWS KMS-managed envelope keys for customers on the clinic plan. The KMS key ARN is auditable on request.

  • Business Associate Agreement

    Available on the HIPAA-eligible tier. BAAs are counter-signed through our e-signature partner; we retain only the SHA-256 hash of the counter-signed document.

  • PHI redaction

    Available on the HIPAA-eligible tier: a deterministic, one-way redactor at every storage / export boundary. Reverse only via the two-person break-glass workflow with full audit trail.

  • Sub-processor inventory

    Published on /trust. Reviewed at least every 12 months; covered entities can subscribe to change notifications.

Live attestation

Run it yourself

Live encryption attestation

The clinic-tier attestation runs every check fromserver/compliance/encryption_attestation.pyand records an audit-log event. Only signed-in customers on the clinic plan can view the live report.

Click Run attestation to verify the live controls. You'll need to be signed in.

For the full sub-processor list and SOC 2 stance, visit /trust. Report a security issue at security.txt.