ChatGenius Trust Center
Enterprise-Grade Security for Healthcare

We protect your patient data with the highest security standards in the industry. Transparency, compliance, and trust are at our core.

🏥 HIPAA Compliant
📜 SOC 2 Type II In Progress
🌎 GDPR Compliant
💳 PCI DSS Level 1
🔒 CCPA Compliant
✅ 99.9% Uptime

Compliance Certifications

Built for healthcare from day one. We meet and exceed the strictest compliance standards in the industry.

🏥

HIPAA

Full HIPAA compliance for protected health information. Business Associate Agreements available.

Compliant
📜

SOC 2 Type II

Security controls aligned with AICPA Trust Service Criteria. Audit in progress.

In Progress — Q3 2026
🌎

GDPR

Full GDPR compliance including data processing agreements, right to erasure, and portability.

Compliant
💳

PCI DSS Level 1

Payment processing meets PCI DSS Level 1 through certified payment partners.

Compliant
📋

CCPA

California Consumer Privacy Act compliance. Full data transparency and consumer rights.

Compliant

📄 Business Associate Agreement (BAA) Template

ChatGeniusX is committed to protecting Protected Health Information (PHI) in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA).

  • ChatGeniusX acts as a Business Associate under HIPAA regulations
  • All PHI is encrypted at rest (AES-256) and in transit (TLS 1.3)
  • Access to PHI is restricted to authorized personnel only
  • Breach notification within 72 hours of discovery
  • PHI is never used for marketing, analytics, or AI model training
  • Data disposal upon termination per HIPAA requirements
  • Annual security risk assessments conducted
  • Subcontractor compliance ensured with downstream BAAs

To execute a BAA, contact our compliance team at compliance@chatgeniusx.com or request one from your account dashboard.

Security Architecture

Military-grade encryption and enterprise infrastructure protect your data at every layer.

🔒

Data Encryption

All stored data is encrypted using AES-256 at rest. All data in transit is protected with TLS 1.3. The same standards used by the U.S. government and financial institutions.

☁️

Infrastructure

Hosted on AWS with multi-AZ deployment for high availability. VPC isolation, private subnets, and automated failover ensure your chatbot is always running.

🛡

Network Security

Enterprise-grade firewall rules, Web Application Firewall (WAF), and DDoS protection via AWS Shield. All traffic is monitored and analyzed in real time.

🔐

Key Management

Encryption keys are managed through AWS KMS with automatic rotation. Keys are hardware-protected and never stored alongside data.

Data Handling & Privacy

You own your data. We never sell, share, or use it for advertising or AI training.

Your Data, Your Rules

  • Data Residency: Primary storage in AWS US-East (Virginia). EU data residency available for Enterprise customers
  • Data Retention: Configurable retention policies. Default 24-month retention with automatic purge options
  • Right to Erasure: Full GDPR Article 17 compliance. Delete all data with one click from your dashboard
  • Data Portability: Export all your data at any time in CSV or JSON format
  • No Data Mining: Your data is never sold, shared, or used for third-party purposes
  • No AI Training: Patient data is never used to train AI models
  • Automated Backups: Daily encrypted backups with 30-day retention and point-in-time recovery
  • Data Integrity: Regular data integrity verification and checksums

📄 Data Processing Agreement (DPA)

Our Data Processing Agreement outlines how ChatGeniusX processes personal data on behalf of our customers, in compliance with GDPR and applicable data protection laws.

  • Lawful basis for processing defined per GDPR Article 6
  • Data subject rights facilitated (access, rectification, erasure, portability)
  • Sub-processor list maintained and updated with advance notice
  • Data transfer mechanisms compliant with EU-US Data Privacy Framework
  • Data breach notification within 72 hours
  • Regular Data Protection Impact Assessments (DPIAs)

Request your DPA at privacy@chatgeniusx.com or download from your account settings.

Access Controls & Authentication

Granular permissions ensure the right people have access to the right data — nothing more.

👥

Role-Based Access Control

Three distinct roles — Head Admin, Admin, and Doctor — each with precisely scoped permissions. No over-privileged accounts.

🔐

Two-Factor Authentication (2FA)

Optional 2FA for all accounts. Supports authenticator apps (TOTP) for an extra layer of security on every login.

📧

Session Management

JWT-based authentication with 8-hour token expiry. Automatic logout on inactivity. Secure, httpOnly token storage.

📄

Audit Logging

Complete audit trail of all account actions. Track who changed what, when, and from where. Immutable and exportable logs.

Uptime & Reliability

Your chatbot is always available when your patients need it.

All Systems Operational

99.9% Uptime SLA

Guaranteed uptime with automated failover across multiple AWS availability zones. Enterprise customers receive contractual SLA guarantees.

🔄

Automated Backups

Daily encrypted backups with 30-day retention. Point-in-time recovery ensures no data is ever lost. Backups stored in a separate geographic region.

Incident History

We maintain full transparency about service incidents and their resolution.

Date Status Description Duration
No incidents reported. All systems have been fully operational.

Penetration Testing & Vulnerability Management

Proactive security testing to identify and eliminate vulnerabilities before they become threats.

🔎

Annual Third-Party Penetration Testing

We engage independent, accredited third-party security firms to conduct comprehensive penetration tests of our infrastructure, APIs, and application layer annually.

📄

Results Available on Request

Penetration testing executive summaries are available upon request for Enterprise customers under NDA. Contact your account manager or our security team.

Security & Compliance FAQ

Answers to your most common security questions.

Do you sign BAAs?+

Yes. We sign Business Associate Agreements (BAAs) with all healthcare customers. BAAs are available on all plans. Contact compliance@chatgeniusx.com or request one from your dashboard to get started.

Where is my data stored?+

All data is stored on AWS infrastructure in the US-East (Virginia) region. For Enterprise customers, we offer EU data residency options. All data is encrypted at rest with AES-256 and in transit with TLS 1.3.

Can I export my data?+

Yes. You can export all your data at any time in CSV or JSON format directly from your dashboard. This includes conversations, bookings, patient records, analytics, and all associated metadata. Your data is always yours.

Do you use my data for AI training?+

No, never. Your patient data, conversation logs, and business information are never used to train AI models. Your data is used exclusively to provide you with our service and nothing else. This is contractually guaranteed in our DPA and BAA.

How do you handle data breaches?+

In the unlikely event of a data breach, we notify affected customers within 72 hours as required by GDPR and HIPAA. Our incident response plan includes immediate containment, forensic investigation, regulatory notification, and remediation steps.

What happens to my data if I cancel?+

Upon account cancellation, you can export all your data. After a 30-day grace period, all data is permanently and irreversibly deleted from our systems, including backups. We provide written confirmation of data destruction upon request.

Start Your Secure Free Trial

14 days free, no credit card required. Your data is protected from day one.

Start Free Trial →