Security & Privacy

Clinical-grade security,
built into every layer.

Privacy isn't a checkbox at Lisner. It's the architecture. Voice never leaves the device. Data is never sold. Consent is always patient-controlled.

HIPAA Compliance

Verified HIPAA compliant.

HIPAA Compliant — Accountable HQ

Verified by Accountable HQ

Lisner's HIPAA compliance program is independently verified and maintained by Accountable HQ. This includes policies, workforce training, risk assessments, and Business Associate Agreement infrastructure.

A BAA is executed with every clinical partner before any PHI enters the system. Contact privacy@lisner.ai to initiate a BAA.

Request BAA →
On-Device Architecture

Voice never leaves the patient's phone.

The most sensitive data — the patient's voice — is processed entirely on-device using WhisperKit. No audio file is ever created, stored, or transmitted. Only the text transcript the patient chooses to share reaches our servers.

🎙️

Voice Capture

Recorded locally, never saved as a file

📱

On-Device Transcription

WhisperKit — runs entirely on the iPhone

Patient Shares

Only text the patient approves leaves the device

🔒

Encrypted Transit

TLS 1.2+ HTTPS — no unencrypted transmission

🗄️

Secure Storage

AES-256 at rest — Google Cloud Firestore

Encryption & Infrastructure

Every layer encrypted. Zero compromises.

Data in Transit

  • TLS 1.2+ enforced for all connections
  • HTTPS-only — no fallback to HTTP
  • Certificate pinning on iOS client
  • All API endpoints require authenticated tokens

Data at Rest

  • AES-256 encryption managed by Google Cloud
  • Firestore access restricted by security rules
  • Role-based access — therapist sees only consented patients
  • No admin backdoor to patient data

Google Cloud Infrastructure

  • Firebase / Cloud Firestore — HIPAA-eligible platform
  • Google Cloud BAA executed with Vira Holdings, Inc.
  • Data hosted in us-central1 (Iowa) region
  • Automatic backups with point-in-time recovery

Access Controls

  • Firebase Authentication — MFA required for clinicians
  • Custom claims enforce role-based data access
  • Patient consent revocation severs access instantly
  • Full audit log of all data access events
Compliance Roadmap

What we have. What we're building.

We believe in transparency about what we've achieved and what we're working toward. We will never claim a certification we don't hold.

✓ Live

HIPAA Compliance

Verified by Accountable HQ. BAA available. Policies, training, and risk assessments in place.

✓ Live

Google Cloud BAA

Business Associate Agreement executed with Google Cloud for Firebase / Firestore PHI handling.

✓ Live

On-Device Transcription

WhisperKit on iOS — voice never transmitted. Zero audio retention by architectural design.

In Progress

Penetration Testing

Third-party security assessment scheduled for Q3 2026 prior to scaled clinical deployment.

Planned Q4 2026

SOC 2 Type II

Audit period initiated as we scale to enterprise clinical customers. SOC 2 Type II target: Q4 2026.

Planned 2027

ISO 27001

Information security management certification aligned with international healthcare requirements.

Contact

Security questions or audit requests?

Our security team responds to all inquiries within one business day. For BAA requests, contact privacy@lisner.ai.