Protect your license · Prove your oversight · Your data stays yours

Private by construction.

You can be named in a suit for a treatment you never saw — so what this protects is the record that speaks for you: your license, your patients' trust, and your practice's data. The sensitive work is done by a private model on our de-identification perimeter, and outside AI services only ever see de-identified data — so privacy isn't a policy you have to take on faith, it's the wiring. BAA available.

This page describes the security architecture of the ProtokolIQ clinical platform. The marketing website you are reading is PHI-free by construction and never receives patient data — see our privacy notice.

Protect your license

A documented good-faith exam for every patient, charting that holds up, and the controlled-substance and delegation logs an inspector expects.

Prove your oversight

Your medical director’s sign-offs become time-stamped, per-patient records, and you can produce an audit trail on demand.

Your data stays yours

Patient data is never sent to outside AI services or sold; the sensitive work runs on private, self-hosted models.

Private perimeter

Sensitive work stays off frontier AI

Private, self-hosted models draft SOAP notes and handle raw clinical context. Audio and transcripts are never sent to a frontier AI provider.

de-identification gate
Frontier · de-identified

Frontier models see only safe data

Anything sent to a frontier model is de-identified first. Patient identity never crosses the gate.

How PHI moves through the system

Conceptual overview — not a deployment diagram.

  1. 1

    Captured

    Patient data enters your tenant — never a shared pool.

  2. 2

    Encrypted at rest

    AES-256-GCM on disk.

  3. 3

    Tokenized

    Identifiers are replaced with vault tokens.

  4. 4

    Processed privately

    A private, self-hosted model does the sensitive work — not a frontier AI provider.

  5. 5

    De-identification gate

    Only de-identified data may pass.

  6. 6

    Audited

    Every model call captured — prompt and response.

Compliance posture

ProtokolIQ's compliance posture: built to the HIPAA Privacy and Security Rules with a Business Associate Agreement available, SOC 2 on the roadmap (never represented as held), PHI encrypted with AES-256-GCM at rest and TLS 1.2+ in transit, tokenized in a vault, isolated per tenant with row-level security, and every AI model call audited — prompt and response. Frontier models see de-identified data only.

HIPAA HIPAA-aligned — built to the Privacy & Security Rules
BAA BAA available
SOC 2 On the roadmap (never "certified")
Encryption At rest: AES-256-GCM · In transit: TLS 1.2+
PHI handling Tokenized in a vault; de-identified before any frontier model
Tenant isolation Per-tenant row-level security
AI audit Every model call captured (prompt + response)
PHI exposure to frontier AI None — de-identified only
Website analytics Cloudflare Web Analytics — cookieless and aggregate; no advertising or cross-site-tracking cookies. Cloudflare may set strictly-necessary security cookies.

Request our security artifacts — BAA, control summary and SOC-2 roadmap, available under NDA — through the founding-practice conversation.

AI that earns trust

You're liable for the treatment room you can't stand in — so nothing that touches care is left to a guess. The AI drafts and surfaces; you decide and sign. Autonomy is earned by demonstrated accuracy and revoked automatically on error.

  1. L0
    Transparent
    Shows its work; you decide everything.
  2. L1
    Suggest
    Recommends with rationale; you approve or modify.
  3. L2
    Confirm
    Prepares the action; you give one-tap approval.
  4. L3
    Auto-execute
    Acts within policy bounds; you see the result.
  5. L4
    Silent
    Acts and surfaces only the exceptions.
GREEN · Auto

Ingestion, scoring, notifications.

AMBER · Confirm

Recommendations, patient communications.

RED · Human-only

Prescribing and dispensing decisions.

Promotions are earned by demonstrated accuracy; demotions are automatic on error. Controls live inline — no settings screens.

Questions counsel asks

Is ProtokolIQ HIPAA compliant?

No vendor can be "HIPAA certified" — only HHS OCR determines compliance for a covered entity. ProtokolIQ is built to the HIPAA Privacy and Security Rules, and we sign a Business Associate Agreement.

Does a frontier model ever see patient data?

No. A private, self-hosted model handles anything PHI-sensitive. Only de-identified data is ever sent to a frontier model, and a de-identification gate sits between the two.

How is one practice isolated from another?

Each practice is a separate tenant, isolated at the database with per-tenant row-level security. One practice can never query another practice’s data.

Is there an audit trail for AI actions?

Yes. Every model call is captured — prompt and response — so an AI action can always be reconstructed and reviewed.

What about SOC 2?

SOC 2 is on our roadmap. We state it as a roadmap item and never represent it as a certification we currently hold.

Can we get a BAA and your security artifacts?

Yes — a BAA is available, and we can share a control summary and our SOC-2 roadmap under NDA. Request them through the founding-practice conversation.

Founding practices · Limited 2026 cohort

Help build the operating system you'll actually run on

You left someone else's way of doing things to run the room your way. We're onboarding a small 2026 cohort of founding practices as design partners — you shape the modules for your clinic type, and pricing is built around what you're replacing and walked through together, not printed on a rate card.

  • Co-design the roadmap
  • White-glove onboarding
  • Founding pricing

A small 2026 cohort — we review every application by hand. No public pricing yet; we'll walk through it together on a short call.