---
title: Security and compliance | Nextvisit
description: HIPAA, SOC 2 Type II, and AI governance practices. Training on patient or provider information requires explicit opt-in. Internal evaluations are enabled by default.
url: "https://nextvisit.ai/security"
type: static
generatedAt: "2026-09-21T03:14:00.641Z"
---

Security and compliance
# Security and compliance built for mental health data.

Security combines independent audits, BAAs, encryption, and documented AI controls.
           HIPAA Compliant     SOC 2 Type II     BAA Available by default           AI governance
## How we govern AI over time.

Internal evaluations are enabled by default and include transcripts and LLM traces to monitor accuracy, quality, and performance. Evaluations are separate from model training. We maintain BAAs and agreements with our AI gateways, model providers, and AI providers.

[Read our AI and subprocessor disclosures](/legal/ai-subprocessors) for provider roles, model routing, retention, redaction, and provider restriction requests.
     How we handle data
## Clear PHI boundaries.

 - Encrypted in transit and at rest (TLS 1.3, AES-256).
- As of 2026, model training on patient or provider information requires explicit opt-in.
- Third-party data, including Google Accounts, Google Calendar, and EHR data, is excluded from training.
- Configurable retention. Recordings deleted on signature.
- SSO, SCIM provisioning, audit logs.
- US-hosted on infrastructure with HIPAA BAAs.
            Responsible AI
### The clinician is always the author.

AriaMD is grounded in retrieved encounter context, uses safety guardrails, and surfaces sources for every assessment. The clinician reviews and signs. The AI never owns the chart.
   [Open the trust center](https://trust.nextvisit.ai) [security@nextvisit.ai](mailto:security@nextvisit.ai)