Security and compliance

Patient trust is the product. Here's how Velaire handles the data that runs through it, what the terms actually mean, and what to ask any vendor in this category, including us.

Trust

Patient data, handled seriously

Built on infrastructure with signed BAAs across every vendor that touches patient data: voice, SMS, and hosting.

Encrypted everywhere

Data is encrypted at rest and in transit across every system that touches a call.

Clinic-level isolation

Role-based access and clinic-level data isolation keep each practice's data separate.

Audit logging

Access, changes, and exports are logged so activity can be reviewed.

BAAs available

Business Associate Agreements are available for approved healthcare deployments.

Plain terms

What the words in this category actually mean

Some of the language vendors use here is marketing rather than law. These three distinctions are worth knowing before you evaluate anyone.

There is no such thing as HIPAA certification

No government body certifies software as HIPAA compliant. Any vendor showing you a HIPAA certificate is showing you something a third party sold them. What actually carries legal weight is a signed Business Associate Agreement between you and each company that handles protected health information on your behalf.

A BAA is the thing that matters

It is the contract that makes a vendor legally accountable for the patient data it touches. Velaire's position is that every vendor in the chain that touches patient data should be under one, and that you should be able to ask who they are.

Compliance is a posture, not a badge

It is about how a system is configured, who can reach the data, and what gets recorded when they do. That is why the pillars below describe practices rather than logos.

Due diligence

Five questions worth asking any vendor

Including us. If a vendor in this category cannot answer these plainly, that is itself an answer.

Which vendors in the chain have signed a BAA?

An AI front office is never one company. Voice, SMS, hosting and any AI model provider each touch the call. A vendor should be able to name every link in that chain, not just itself.

Where does the call audio and transcript actually live?

Recording and transcription are the most sensitive surface in the whole system, and they are usually handled by a third party rather than the vendor selling to you.

Who on your side can see our data, and is that logged?

Access controls matter less than whether access is recorded. Ask whether staff access is audited and whether you can see that audit trail.

What happens to our data if we leave?

Retention and deletion terms are easier to agree before signing than after. Ask what is kept, for how long, and what deletion actually removes.

Can you show this in writing?

A claim on a marketing page is not an agreement. The BAA and the data-processing terms are the documents that bind anyone.

Our answer to question one

Every vendor that can touch a patient call

This is the chain we would want to see from anyone else. Each row is what that vendor does, the patient data it can reach, and where it processes it.

Retell AI

Live call audio, the speech-to-text transcript, and any clinical detail the caller volunteers during the conversation.The most sensitive vendor in the chain, because it holds the audio and the transcript rather than just metadata.
Voice agentProcessed in: United StatesAgreement: Direct BAA

Twilio

The phone number on both ends of the call, call duration and routing metadata, and the contents of any SMS sent back to the patient.On a Retell-managed number, Twilio operates as Retell's subprocessor and sits under Retell's agreement rather than a separate one. On a bring-your-own-carrier setup that is not true and a direct agreement is needed.
Telephony and SMSProcessed in: United StatesAgreement: Covered under Retell's BAA

Amazon Web Services

Stored patient records: name, callback number, the reason for the call, call transcripts and recordings, consent records and opt-out state.Consent and opt-out are enforced here by database constraints and a trigger rather than by application code, so a stray script or a hand-run query cannot bypass them.
Database and application hostingProcessed in: United States (us-east-2)Agreement: Direct BAA

Vercel

Anything submitted through a form on this website. No patient records, no call content: the clinic-facing application and its database are not hosted here.
Marketing website hosting and DNSProcessed in: United StatesAgreement: No patient data — BAA not required

Supabase

What you type into a form on this website: your name, your practice's name, your email address and your phone number. No patient records and no call content — the clinic-facing application and its database are not here.This is the sales enquiry record, not the product. A practice's own patients, calls and appointments are in Amazon RDS and never reach it.
Enquiry CRMProcessed in: United States (us-east-1)Agreement: No patient data — BAA not required

Google Workspace

Any patient detail that appears in an email notification sent to the practice, such as a message taken from a caller.
EmailProcessed in: United StatesAgreement: Direct BAA

Cal.com

The name, email address and chosen time of whoever books a demo on this site. That is a practice's own staff arranging a sales call, never a patient. It is not present on a call, in the agent, or on any page where a patient enters their details.Loads only on the demo page, and only because a visitor went there to pick a time. Unlike analytics it is available in every market, since a calendar someone deliberately opened is the service they asked for rather than observation they did not.
Demo schedulingProcessed in: United StatesAgreement: No patient data — BAA not required

Google Tag Manager and Google Analytics

Pages viewed on this marketing site, plus the IP address and browser the request came from. It is not present on a call, in the agent, or on any page where a patient enters their details.Listed last because it never sees a call. It loads only in the markets named in our analytics policy and is absent from the rest, because those markets require opt-in consent that this site does not yet ask for.
Website analyticsProcessed in: United StatesAgreement: No patient data — BAA not required

What we do not claim

The absence of these is worth more to you than another badge would be.

  • + We are not SOC 2 certified, and we do not display a SOC 2 badge.
  • + We are not ISO 27001 certified.
  • + We hold no HITRUST certification. No AI receptionist vendor we reviewed holds one either.
  • + We do not have a signed agreement with any electronic health record vendor, so Velaire does not write into your chart. It captures the request and hands it to your front desk.
  • + We do not claim that patient data stays inside any single country beyond the regions named above.

We wrote a longer version of this as an evaluation guide, covering what separates a real deployment from a demo.

Messaging patients raises a separate set of questions from storing their data. What we send, what we keep as proof of permission, and what stops it.

FAQs

Security questions

HIPAA does not certify software, so no honest vendor can hold up a certificate. What matters is that a Business Associate Agreement is in place with every vendor that handles protected health information, and that the system is configured accordingly. BAAs are available for approved healthcare deployments. Ask us for the specifics that apply to your practice.
Yes. At the voice platform, call audio and the transcript are deleted after 30 days. Before that window closes we copy both into our own Google Workspace storage, and that copy is kept for as long as the practice has an account with us — so audio does outlive the 30 days, and we would rather say so than let the first number stand on its own. The structured record of the call — who rang, when, what they asked for, what was booked — is kept on the same basis. Neither has an automatic purge yet. If you need a shorter window or a specific retention policy matched, raise it before go-live and it goes in the agreement.
Access is role-based and isolated per clinic, so one practice's data is not reachable from another's. Access, changes, and exports are logged so activity can be reviewed.
Data is encrypted at rest and in transit across every system that touches a call.
HIPAA is US-specific. Other markets have their own frameworks, such as UK GDPR and the Australian Privacy Act, and the right handling for those is confirmed per market rather than assumed from the US posture.
Let’s make room for better care

Your next caller
could be your next patient.

See how Velaire would handle the calls your practice misses. A personal walkthrough, built around your questions.

Let’s talk about your practice