Access control
- · Every user has their own named account; shared logins are not permitted.
- · Roles grant the least access a job needs, and are reviewed quarterly.
- · Sensitive or irreversible actions require re-entering a password, and some require a second, different approver.
- · Access is removed the day someone leaves or changes role.
Protecting data
- · Encrypted in transit (TLS) and at rest.
- · Only the minimum fields a conversation needs are stored outside the record system.
- · Clinical notes never leave the record system.
- · Backups are encrypted, and restores are tested.
Audit and accountability
Every outreach, interpretation, write-back, override and access event is logged with the actor, timestamp and reason. Logs are append-only in production and retained for the period the practice's regulator requires.
Change management
Changes go through review, automated checks and a staged release. Configuration changes to rules, templates and thresholds are versioned, attributed and reversible.
Incident response
Suspected incidents are triaged within one working day, contained, investigated with a written timeline, and closed with corrective actions. Affected customers are informed without undue delay, and within 72 hours where personal data is involved.
Vendor and sub-processor assurance
Before a vendor touches customer data we check its security posture, ask for its current independent audit report where one exists, and put a written agreement in place. Evidence is tracked with expiry dates so nothing lapses unnoticed.
What is not yet in place in this prototype
Being explicit matters more than looking finished. In this environment:
- · Integrations with the record system and messaging are simulated, not live.
- · Audit storage is not yet write-once hardware-backed storage.
- · No independent audit or penetration test has been performed on this build.
- · Signed agreements with hosting, messaging and AI vendors are a go-live requirement, not a completed step.
Reporting a vulnerability
Email hello@byov.ai with enough detail to reproduce. We acknowledge within two working days and will not pursue good-faith researchers who avoid privacy violations, data destruction and service disruption.