Privacy is the architecture.
A clinical record is as personal as data gets. We treat it that way in the database, not just in the policy.
How your data is protected
Captured with consent
Recorded, versioned consent before anything is captured. Withdraw consent and capture stops.
Encrypted in transit and at rest
TLS 1.3 on the wire, AES-256 in storage.
Row level access control
Only the client and their care team can reach a record. Enforced in the database, not just in the app.
Every access logged
A full audit trail, with export and permanent deletion in one click.
Stored in Canada
Canadian data residency for PHIPA and PIPEDA.
PHIPA, PIPEDA & HIPAA aligned
Architected for Ontario and Canada, aligned for US practices. A BAA is available; a SOC 2 Type II examination is underway.
Consent gated, always
Nothing is captured without recorded consent, and withdrawing it stops capture immediately.
Yours, never sold
Never used to train any model without opt in consent. Nothing is shared or sold.
You sign every document
A licensed clinician authors the record. Qull never files a document on its own.
Export & delete
Full data portability and permanent erasure, on request, audio and all.
Encrypted everywhere
AES-256 at rest, TLS 1.3 in transit, private storage reachable only through short lived signed links.
For your privacy officer
The details, on the record.
Where is data stored?
In Canada, for PHIPA and PIPEDA data residency. Recordings live in a private store reachable only through short lived, signed links.
Who can see a client’s record?
Only that client and their care team. Access is enforced row by row in the database, not just in the app, and every access is logged.
Do you train models on our data?
Never without explicit, opt in consent. By default a record is used only to produce that client’s care and notes. Nothing is sold or shared.
Can we export or delete everything?
Yes. One click exports a complete copy of a client’s record, or permanently deletes it, audio and all.
What about certifications?
Qull is architected for PHIPA, PIPEDA, and HIPAA, and a SOC 2 Type II examination is underway. We are happy to walk your team through the controls.
Bring your privacy officer.
We’ll walk through the architecture, the controls, and the paper trail, question by question.
Book a security review →