Security & compliance
How Vestibo protects your customers.
A HIPAA-eligible tier, a SOC 2 program in progress, and encryption controls you can attest from your account.
Encryption attestation · KMS · HIPAA-eligible tierWhat we commit to
Six commitments, plain English.
Each commitment maps to a control in our SOC 2 readiness program (audit not yet completed) and to a clause in our standard BAA. Click any tile for the technical detail.
Encryption at rest
Integration credentials and OAuth tokens are encrypted at the application layer with Fernet (AES-128-CBC + HMAC-SHA256), keys held outside the application image. Transcripts, audit logs, and backups are encrypted at rest by AWS storage (RDS/S3). Keys can be rotated on demand.
Encryption in transit
TLS 1.2+ enforced on every public endpoint. HTTP requests redirect to HTTPS at the edge; HSTS is on.
Cloud KMS
AWS KMS-managed envelope keys for customers on the clinic plan. The KMS key ARN is auditable on request.
Business Associate Agreement
Available on the HIPAA-eligible tier. BAAs are counter-signed through our e-signature partner; we retain only the SHA-256 hash of the counter-signed document.
PHI redaction
Available on the HIPAA-eligible tier: a deterministic, one-way redactor at every storage / export boundary. Reverse only via the two-person break-glass workflow with full audit trail.
Sub-processor inventory
Published on /trust. Reviewed at least every 12 months; covered entities can subscribe to change notifications.
Run it yourself
Live encryption attestation
The clinic-tier attestation runs every check fromserver/compliance/encryption_attestation.pyand records an audit-log event. Only signed-in customers on the clinic plan can view the live report.
Click Run attestation to verify the live controls. You'll need to be signed in.