Security & governance

Built for your diligence review.

Everything below is one line here and a full document in the diligence pack. Ask for it.

HIPAA / HITECH adherence

The federal rules for handling health information. We follow them.

SOC 2 Type II-aligned controls

Our security practices follow the SOC 2 Type II framework.

BAAs with all subprocessors

Signed agreements hold every vendor we use to the same privacy rules.

Tenant-scoped isolation

Each organization's data lives separately from every other's.

Encryption in transit and at rest

Data is encoded while moving and while stored.

PHI minimization

Carrie handles only the personal health information a Program needs, nothing more.

TCPA-compliant outbound, with STIR/SHAKEN

Calls follow federal calling rules, and carriers can verify they really come from your practice.

Model-agnostic AI layer

Carrie's AI layer swaps models as better or safer ones emerge, so the platform is never tied to a single AI vendor.

Consent, embedded

Patient consent sits in the practice's standard and procedural consents, the paperwork patients already sign.

How the AI is governed.

Every call runs a Program: a version-controlled clinical playbook, immutable once released. A second, independent AI checks every sentence of every call in real time for emergencies. The Human Oversight Team, licensed clinicians, verifies every flagged concern, urgent ones within 1 hour. And every conversation lands in an immutable audit log that can be replayed exactly. The full governance model is on How Carrie works.

Carrie never diagnoses, prescribes, or places orders; clinical judgment stays with the care team.

Your security team will have questions. The pack answers them.

Request the diligence pack Book a scoping call