Security & compliance
How Vestibo protects your customers.
A HIPAA tier in development and a SOC 2 program in progress. Your data is encrypted in transit and at rest today.
Encryption attestation · KMS · HIPAA tier in developmentWhat we commit to
Six commitments, plain English.
Each commitment maps to a control in our SOC 2 readiness program. The audit is not complete, so no attestation report exists yet.
Encryption at rest
Integration credentials and OAuth tokens are encrypted at the application layer with Fernet (AES-128-CBC + HMAC-SHA256), keys held outside the application image. Transcripts, audit logs, and backups sit in the database, which AWS RDS encrypts at rest. Keys can be rotated on demand.
Encryption in transit
TLS 1.2+ enforced on every public endpoint. HTTP requests redirect to HTTPS at the edge; HSTS is on.
Cloud KMS
At-rest keys are managed in AWS KMS, where automatic rotation is available. The key ARN is auditable on request.
Business Associate Agreement
We sign BAAs only on the Clinic tier, which is not offered or purchasable today. No e-signature provider is engaged yet, so no BAA can be signed right now.
PHI redaction
Part of the HIPAA tier in development: a deterministic, one-way redactor applied to knowledge content as it is ingested. Redaction is permanent — the original is not retained and cannot be recovered.
Sub-processor inventory
The authoritative list is published at /legal/subprocessors. We give 30 days' notice before adding a sub-processor. Email privacy@vestibo.com to follow changes.
Run it yourself
Live encryption attestation
The clinic-tier attestation runs every check fromserver/compliance/encryption_attestation.pyand records an audit-log event. Only signed-in customers on the clinic plan can view the live report.
Click Run attestation to verify the live controls. You'll need to be signed in.