Trust and security

A text message is not a safe place for health information. So we don’t put any there.

The text carries a random link code. Everything else sits behind an identity check, and the secrets that would let someone in are never stored in readable form.

The secure link

What protects each member’s link.

No PHI in texts

Nothing to read in the message

Texts name the plan and the assessment, never a condition, answer or member ID.

Random codes

Codes can’t be guessed

Each link uses a long random code, and only a keyed hash of it is stored.

Bot-safe

Link previews do nothing

Opening the link changes nothing until a person acts, so messaging-app previews can’t use it up.

Identity first

Verified before any health information

The member confirms the fields their state requires. Dates of birth are compared as keyed hashes, not stored in plain text.

Lockout

Guessing is stopped

Five wrong answers lock the link for 30 minutes.

Short sessions

Shared phones stay private

Sessions end after 30 minutes idle or 4 hours in total.

Consent and messaging

Texting that follows the rules every time.

  • Texts go only to members with valid consent on file.
  • Messages wait for quiet hours to end in the member’s own time zone.
  • STOP takes effect at once and syncs back to your systems.
  • Inbound delivery and reply webhooks are signature-checked before they are trusted.
  • Sending numbers are registered with carriers for business texting.

Platform controls

Controls your security review will ask about.

  • Encryption in transit and at rest.
  • Role-based access scoped by plan, state and line of business, with single sign-on.
  • Audit trail for form approvals, rule changes, overrides and data exports.
  • Business associate agreement with every plan before any member data is shared.
  • Full export of your data and configuration in open formats.

Certifications

Audits and attestations.

Placeholder[SOC 2 Type II][Status and report date, once confirmed]
Placeholder[HITRUST][Status, once confirmed]
Placeholder[Penetration test][Most recent test date and firm]

List only certifications that are held, with dates.

Need our security documentation?

We’ll share architecture and control details under NDA as part of your review.