Skip to content
Aurantis AI

Security approach

Security questions belong to the complete patient-access workflow.

A serious review covers the deployment, vendors, contracts, configuration, access, data paths, operational ownership, and escalation—not only the conversational interface.

Planning principles

Build the responsibility model before the workflow goes live.

These principles are evaluation areas, not certification claims.

01

Data minimization

Define which information each workflow actually needs before collecting it.

02

Access permissions

Map access to job responsibilities, connected systems, and workflow scope.

03

Transmission and storage

Review data paths, vendors, retention, and deletion expectations for the full deployment.

04

Auditability

Establish appropriate visibility into workflow actions, handoffs, and administrative outcomes.

05

Human escalation

Define what transfers immediately, what is captured, and what remains outside automation.

06

Approved knowledge

Keep administrative responses aligned with information and policies supplied by the practice.

Responsibility model

The practice and the vendor each have work to do.

Responsibility should be explicit across configuration, approved information, user access, connected systems, contracts, staff procedures, monitoring, and incident handling.

Access control

Define roles, connected-system permissions, administrative privileges, and review procedures for the intended deployment.

Data transmission

Map each data path, vendor boundary, transfer destination, and fallback before production use.

Storage and retention

Determine what must be stored, where, for how long, and how deletion or retention obligations are managed.

Logging and auditability

Establish appropriate records of administrative actions, configuration changes, access, transfers, and exceptions.

Incident response

Document vendor notification, investigation, containment, practice coordination, and contractual responsibilities.

Practice-specific review

Evaluate workflows, systems, vendors, agreements, safeguards, and operational use for the individual practice.

Subprocessors and vendors

The full vendor chain should be identified for the selected voice, telephony, hosting, integration, messaging, analytics, and workflow services.

No subprocessor list is published here until it is complete, current, reviewed, and approved for public release.

Contracts and documentation

A BAA discussion is implementation-specific.

Contractual arrangements, vendor roles, data handling, and the intended workflow must be reviewed together. This page does not state that a BAA is available because that position has not been verified for publication.

No certification or contractual badges are currently displayed.

Verified claims can be enabled from the structured security registry after evidence and approval are recorded.

Important scope statement

Security and compliance depend on the complete deployment, vendor relationships, contractual arrangements, configuration, and operational use—not only the marketing website.

This page describes implementation questions and does not provide legal advice.

A focused working session

Bring your security questions into the workflow discussion.

We can review the intended call path, systems, vendors, data needs, transfers, and documentation your evaluators require.

Book a private demo

No patient information is needed for the demo.