Security

Architecture of Trust

Clinical data is protected at the highest level - security is an integral element of system architecture.

Below is the full map of the safeguards actually running in the application.

European infrastructure

Data is stored on Microsoft Azure servers in the European Union. Selected subprocessors (e.g. Stripe for payment processing) may process data outside the EEA under Standard Contractual Clauses. Video sessions run on our own LiveKit instance inside our Azure VNet, so the audio and video stream never reaches another provider’s public cloud.

Therapist at the centre

AI supports the analysis of material but does not make clinical decisions. Azure OpenAI operates in inference mode - data is processed at the moment of the query and is neither retained nor used to train models. Full control over the documentation stays with the therapist.

Data vault

Data is held in a single database with logical separation per therapist and per patient. Therapeutic content (notes, transcripts, conceptualisations) is encrypted with Always Encrypted - the encryption keys live in Azure Key Vault, and the database server never sees that content in plain text.

Technical Safeguards

Multi-layered Protection

We use security standards applied in banking and healthcare.

Every layer works independently - breaching one does not compromise the others.

Always Encrypted (stronger than TDE)

Notes, transcripts and conceptualisations are encrypted on the application side - the SQL server receives an encrypted byte string and has no access to the plain text. CMK keys are stored in Azure Key Vault. Only the therapist has access to session content; a narrow group of system administrators holds the technical permissions needed to maintain the platform and recover data - that access is logged and covered by confidentiality obligations.

Pseudonymisation before sending to AI

Before anything reaches the model, data is pseudonymised locally: patient names are replaced with tokens ([PATIENT]), third parties with [PERSON_1], and national ID numbers, phone numbers and e-mail addresses are detected and removed automatically. The system keeps consistent labels for the same person across a patient’s history without revealing their identity.

Two-factor authentication (2FA/MFA)

Sign-in is protected by multi-factor authentication: a TOTP app (Google Authenticator, Microsoft Authenticator) or a one-time code by e-mail or SMS. Password policy: 16 characters minimum, lower- and upper-case letter, digit and special character. After 5 failed attempts the account is locked for 15 minutes.

Login rate limiting and bot protection

A maximum of 5 sign-in attempts per minute from a single IP address. Rate-limiting mechanisms that cap the number of sign-in attempts protect the system against automated attacks and password guessing (brute force, credential stuffing).

Video sessions on our own infrastructure

Video consultations run in a separate, private environment within our Azure infrastructure. Recordings (Egress) go straight to our own Azure Blob Storage - a secured data store. Each patient receives an individual, unique access link tied to that specific consultation (VideoInviteToken).

Access and change log

Every access to patient data is recorded (who, when, which action). The therapy session change log shows the full edit history of the notes. Logs follow retention policies aligned with the GDPR and are cleared automatically once the statutory periods expire.

Right of access, export and erasure

Full delivery of GDPR rights under Articles 15-22: at the patient’s request we will generate a package containing their data (JSON export) or permanently delete the account together with the notes. The operation is documented in the audit log.

Daily backups

Automatic database backups with geo-redundancy in a European secondary region. Backups are encrypted. Video session recordings and transcripts are stored in Azure Blob Storage with versioning enabled.

Regulatory Compliance

Standards

The system operates in compliance with applicable European and international regulations. Only the therapist has access to therapy session content; administrators' service access is logged and covered by confidentiality obligations.

GDPR

Full compliance with the General Data Protection Regulation (in particular Article 9 - special categories of data, including data concerning mental health).

AI Act

Compliance with the European Artificial Intelligence Act - the system runs in inference mode without automated clinical decisions.

ISO 27001-aligned processes

We apply information security management procedures based on the requirements of ISO/IEC 27001:2022 - risk management, access control, audit and business continuity.

SOC 2-aligned processes

We work in line with the AICPA Trust Services Criteria (Security, Availability, Confidentiality, Privacy) - environment separation, monitoring and incident response.

Therapy Support · Get started today

Reclaim Time for Yourself
and Your Patients

Are you a CBT therapist?
See how the platform supports your daily work.
Session summaries that organize clinical material. Administration that doesn't get in the way.