Security & privacy

How Orvexa AI protects clinic and patient data.

Physiotherapy records are sensitive. These are the controls Orvexa AI uses today to protect your clinic and your patients.

In place today

Six controls built into how Orvexa AI handles data.

  • Clinic data stays separated

    Every record belongs to one clinic organization. Database row-level security and role checks on every API request keep one clinic's data invisible to another.

  • Role-based access

    Owners, admins, physiotherapists, and staff each get only the actions their role needs. Connecting systems and changing settings is limited to owners and admins.

  • Encrypted connections and credentials

    Traffic is encrypted in transit with TLS. Credentials for connected systems such as Cliniko and Slack are encrypted on the server and never sent back to the browser.

  • Physiotherapist approval

    Reports are drafted from your source systems, but a physiotherapist reviews the data and approves every report before it can be downloaded or shared.

  • Data minimization

    Orvexa AI reads approved fields for a report run and generates the PDF without storing patient values in its report tables. Your clinic systems remain the source of truth.

  • No patient data in AI drafting or notifications

    AI only helps draft report and form templates from your clinic's instructions; it never receives patient records. Slack notifications carry the event type and a link, never names, answers, or report content.

Compliance

Working toward formal certification.

We are aligning our controls with SOC 2 and with Canadian and US health-privacy obligations, including PHIPA, PIPEDA, and HIPAA. Orvexa AI does not yet hold a SOC 2 report or certification. Request our current security documentation.

Responsible disclosure

Found a security issue?

Reach us through the contact form with “CONFIDENTIAL SECURITY REPORT” in your message. Please don't include patient information or credentials. We acknowledge reports within two business days.