Your data stays yours.
Plain-English commitments, not legal jargon. If something on this page is unclear, email hello@territoryintelpro.com.
PHI auto-redacted before the model.
Every message a rep sends to the AI coach is redacted on the server before it reaches the model. Names, dates of birth, phone numbers, email addresses, and SSNs are stripped from the prompt. The model never sees them.
You can read the redaction contract in our code: docs/phi-redaction.md (coming soon).
Row-level security on every query.
Authorization is enforced at the database, not in the application layer. A rep can only see rows that match their scope (own / team / org). Even a bug in the front-end cannot leak rows outside the policy.
No PHI. By design.
Referrals are tracked by an auto-assigned referral number, never a patient name. Every free-text field (referral notes, activity logs, custom fields) scans what you type and rejects names, dates of birth, SSNs, MRNs, phone numbers, email addresses, and street addresses before anything is saved. There is no patient data to breach, because there is no patient data.
Encryption at rest and in transit.
All traffic uses TLS 1.2+ with modern ciphers. Database snapshots and backups are encrypted at rest with AES-256. Receipts are stored in encrypted object storage. Session tokens rotate on every privilege change.
Data retention and deletion.
Visit notes, referrals, expenses, and accounts are kept for the lifetime of the org. When an owner closes an org, we delete every row within 30 days. You can export every byte of your data any time via /contact.
HIPAA posture.
Territory Intel Pro is not itself a HIPAA-covered entity, but it's built on infrastructure (Supabase, Vercel) that supports HIPAA-eligible deployments. We sign Business Associate Agreements with Enterprise customers. Talk to us before onboarding a covered entity.
Questions we haven't answered?
We'd rather hear from you than guess. Email the founders directly.
Talk to us