23 questions to ask any vendor
Including us. Take this to every vendor you are considering and compare the answers. No email required, nothing to download.
Each row is a question, why it matters, and how we answer it. The right-hand column is the part worth comparing: a vendor that cannot answer plainly, or that answers with a badge instead of a name, has told you something.
Your ticks are saved in this browser only. Nothing is sent to us, and there is no account.
— of 23 asked
Who touches the data
Name every vendor in the chain that can reach patient data.
An AI front office is never one company. Voice, telephony, hosting and any model provider each touch the call.
Our answer
Published by name on our security page, with what each one touches and the region it processes in. Not a badge, a list.
Which of those vendors are covered by a Business Associate Agreement (BAA)?
A vendor's own assurance does not extend to its subprocessors unless an agreement says so.
Our answer
Stated per vendor, including where one sits under another's agreement rather than holding its own.
Where is the call audio processed, and where is the transcript stored?
Audio and transcript are the most sensitive surface in the system, and usually the part a third party handles.
Our answer
Named vendor and named region for each, on the public page rather than on request.
Ask which states' recording-consent rules you fall under.
Getting this wrong is a compliance problem that surfaces during an audit, not during a sales call.
Our answer
Answered plainly, including when the honest answer is that a requirement cannot be met.
What the AI is allowed to do
Does the agent assess symptoms or decide how urgent a caller is?
That is triage. It is a clinical act, and an automated system performing it is a liability question for the practice, not the vendor.
Our answer
No, and it is not configurable. Several vendors in this category sell exactly this.
Can it give medical advice, or touch a prescription?
Capturing a repeat request is administrative. Approving or confirming one is not.
Our answer
It captures requests and hands them over. It does not approve, submit or confirm anything.
What happens when someone describes an emergency? Ask to hear it, not read about it.
Every vendor claims appropriate escalation. Few will play you the recording.
Our answer
The agent stops, directs the caller to 911, creates no appointment, and notifies the practice with a transcript. The full exchange is published on our safety page.
Does the caller know they are speaking to software?
Some vendors advertise that patients cannot tell. That is a choice they made, and you inherit it.
Our answer
The agent identifies itself on every call. We do not offer a configuration that hides it.
Who can change what the agent is allowed to do, and is that logged?
A boundary that a support agent can switch off is not a boundary.
Our answer
The clinical boundary is fixed in the product, not a per-account setting.
Consent and messaging
Under what consent do you message a patient, and how does that satisfy the TCPA, and state two-party recording consent where it applies?
The practice is usually the party exposed if a message goes out without a lawful basis.
Our answer
Every send must cite a consent record whose purpose covers it. That rule is enforced by database constraints, not by application code.
How does a patient opt out, and what stops a later message from going anyway?
Most systems record an opt-out and then rely on code remembering to check it.
Our answer
A database trigger blocks any send to a number with an active opt-out. A stray script or a hand-run query cannot bypass it.
Can consent be edited or deleted after the fact?
If a consent record can be changed, it is not evidence.
Our answer
Consent is append-only by database privilege. The runtime role has UPDATE and DELETE revoked; withdrawal is stamped by a trigger.
Show me the proof for one specific message you sent.
This is the question that separates a policy from a mechanism.
Our answer
Each send is tied to the consent record that permitted it, by foreign key, so the link cannot be missing.
Recording and retention
Is the call recorded, is the caller told, and when in the call are they told?
A disclosure at the end of a call is not a disclosure.
Our answer
Configured with you before go-live and stated in the agreement rather than set unilaterally.
How long is audio kept, how long is the transcript kept, and are those different?
They usually are, and the transcript usually outlives the audio.
Our answer
Set per practice during onboarding. If you have a retention policy to match, raise it before go-live.
Is our call content used to train shared models?
This is the question most likely to have an uncomfortable answer buried in a privacy policy.
Our answer
No. Ask any vendor to confirm this in writing rather than on a marketing page.
What does deletion actually remove, and from which systems?
Deleting from a dashboard rarely deletes from a subprocessor.
Our answer
Answered per vendor in the chain, because that is the only way the answer is true.
When it goes wrong
What happens to a call the agent cannot handle?
The failure path matters more than the happy path, and it is rarely demonstrated.
Our answer
It routes to a live line or takes a message for callback, based on how it is configured for your practice.
How would we find out the agent got something wrong?
A system with no exception queue is a system that fails silently.
Our answer
Calls, requests and outcomes are visible in one dashboard your practice manager can audit.
Who is accountable, and what does the contract say about it?
A claim on a marketing page is not an agreement.
Our answer
The configuration is agreed in writing before go-live, and the clinical boundary is not something a configuration change can unlock.
The claims themselves
You show a certification badge. Which body issued it, and can I see the report?
Badges are frequently self-declared, or belong to the vendor's cloud provider rather than the vendor.
Our answer
We hold no SOC 2, ISO 27001 or HITRUST certification and we do not display badges implying otherwise. HIPAA does not certify software.
Your site claims an integration. Is it listed in that vendor's own partner directory?
Directories are public and take ten seconds to check. Several vendors claim official integrations they do not have.
Our answer
We are in no vendor directory, and we say so. Velaire captures the request and hands it to your front desk rather than writing into your chart.
Can I speak to a practice like mine that is running this today?
The single most reliable filter in this category, and the one most vendors cannot pass.
Our answer
Ask us. If we do not have a reference that matches your practice type, we will tell you that instead of pointing at a logo wall.
Where our answers come from
The vendor chain and what each subprocessor touches are published in full. So is the clinical boundary, including a transcript of the agent refusing a call it should not take.
Your next caller
could be your
next patient.
See how Velaire would handle the calls your practice misses. A personal walkthrough, built around your questions.
Let’s talk about your practice