Security & privacy
How Orvexa AI protects clinic and patient data.
Physiotherapy records are sensitive. These are the controls Orvexa AI uses today to protect your clinic and your patients.
In place today
Six controls built into how Orvexa AI handles data.
Clinic data stays separated
Every record belongs to one clinic organization. Database row-level security and role checks on every API request keep one clinic's data invisible to another.
Role-based access
Owners, admins, physiotherapists, and staff each get only the actions their role needs. Connecting systems and changing settings is limited to owners and admins.
Encrypted connections and credentials
Traffic is encrypted in transit with TLS. Credentials for connected systems such as Cliniko and Slack are encrypted on the server and never sent back to the browser.
Physiotherapist approval
Reports are drafted from your source systems, but a physiotherapist reviews the data and approves every report before it can be downloaded or shared.
Data minimization
Orvexa AI reads approved fields for a report run and generates the PDF without storing patient values in its report tables. Your clinic systems remain the source of truth.
No patient data in AI drafting or notifications
AI only helps draft report and form templates from your clinic's instructions; it never receives patient records. Slack notifications carry the event type and a link, never names, answers, or report content.
Compliance
Working toward formal certification.
We are aligning our controls with SOC 2 and with Canadian and US health-privacy obligations, including PHIPA, PIPEDA, and HIPAA. Orvexa AI does not yet hold a SOC 2 report or certification. Request our current security documentation.
Responsible disclosure
Found a security issue?
Reach us through the contact form with “CONFIDENTIAL SECURITY REPORT” in your message. Please don't include patient information or credentials. We acknowledge reports within two business days.