Vestibo

Security & compliance

How Vestibo protects your customers.

A HIPAA tier in development and a SOC 2 program in progress. Your data is encrypted in transit and at rest today.

Encryption attestation · KMS · HIPAA tier in development

What we commit to

Six commitments, plain English.

Each commitment maps to a control in our SOC 2 readiness program. The audit is not complete, so no attestation report exists yet.

  • Encryption at rest

    Integration credentials and OAuth tokens are encrypted at the application layer with Fernet (AES-128-CBC + HMAC-SHA256), keys held outside the application image. Transcripts, audit logs, and backups sit in the database, which AWS RDS encrypts at rest. Keys can be rotated on demand.

  • Encryption in transit

    TLS 1.2+ enforced on every public endpoint. HTTP requests redirect to HTTPS at the edge; HSTS is on.

  • Cloud KMS

    At-rest keys are managed in AWS KMS, where automatic rotation is available. The key ARN is auditable on request.

  • Business Associate Agreement

    We sign BAAs only on the Clinic tier, which is not offered or purchasable today. No e-signature provider is engaged yet, so no BAA can be signed right now.

  • PHI redaction

    Part of the HIPAA tier in development: a deterministic, one-way redactor applied to knowledge content as it is ingested. Redaction is permanent — the original is not retained and cannot be recovered.

  • Sub-processor inventory

    The authoritative list is published at /legal/subprocessors. We give 30 days' notice before adding a sub-processor. Email privacy@vestibo.com to follow changes.

Live attestation

Run it yourself

Live encryption attestation

The clinic-tier attestation runs every check fromserver/compliance/encryption_attestation.pyand records an audit-log event. Only signed-in customers on the clinic plan can view the live report.

Click Run attestation to verify the live controls. You'll need to be signed in.

For the full sub-processor list and SOC 2 stance, visit /trust. Report a security issue at security.txt.