Security
How we handle your patients' records
Almost everything in Valence is PHI, and most of it is the kind people are least willing to have leak. This page says what we do with it: where it is stored, who can reach it, which companies touch it, and what happens to the audio from a session. Where the answer is uncomfortable, it is written down anyway.
Last reviewed 9 September 2026 against the running code.
Session audio and AI notes
Sessions are not recorded. A recording only starts when a clinician turns AI notes on during that particular session, and everyone in the call, patients included, sees a recording indicator for as long as it is on.
When one does start, the audio goes from the video server we run to storage in our own AWS account, and it stays there. Transcription happens on the same infrastructure: a Whisper model loaded into our own worker process turns the audio into text. No speech-to-text company receives the recording. This is the part most ambient scribes cannot say, because they send session audio to a cloud transcription vendor and then explain how quickly it gets deleted afterwards.
What we send to Anthropic
Drafting the note is a language model job, and that model is Anthropic's. So text does leave our infrastructure at that step, and it is worth being precise about which text. The request carries the session transcript, excerpts of the last three notes that clinician signed for that patient, that patient's assessment scores and how often they have been seen, and a few samples of the clinician's own past edits so the draft sounds like them.
It does not carry the patient's name, date of birth, address, phone number, or email. Names spoken aloud during the session are in the transcript, the same way they would be in any note. The draft comes back, the clinician edits it, and nothing is used to train a model.
The chart's session prep talking points are built on our own servers from the patient's assessment scores. A practice can choose to have Anthropic reword them, which sends those facts (safety-item flags, top-of-scale symptoms, and score changes) but no name or contact details. That setting is off until a practice admin turns it on.
What we keep, and for how long
The transcript is erased the moment the clinician signs the note. The row stays behind so the chart history still shows that a transcript existed and when, but the text itself is gone and the app returns it empty from then on.
The audio is deleted as soon as the draft note is produced. Not on a nightly job, not after thirty days: the same worker that writes the draft deletes the recording, every participant's track included. Behind that, a storage rule removes anything still in the bucket after three days, which covers a transcription that failed and is waiting to be re-run.
While it does exist, the audio is encrypted at rest in our own AWS account. Nothing in the product plays it back and no vendor can read it.
Where the data lives
One database schema per practice
Every practice gets its own Postgres schema. A query runs inside one schema, so there is no shared patients table with a practice column where a forgotten filter would hand you someone else's caseload. The separation is a property of the database connection rather than a rule the application has to remember, which is the difference that matters when someone writes the next feature in a hurry.
Encryption
Traffic to the app is HTTPS only, TLS 1.2 or better, with plain HTTP redirected at the edge. Session cookies are marked secure and are scoped to your practice's own subdomain, so a session on one practice's host is never sent to another's.
The database is encrypted at rest. Files, including session audio and any uploads, live in a bucket encrypted with a KMS key created for that bucket alone, with automatic key rotation on. The bucket blocks public access outright.
Region and backups
Everything runs in AWS in the United States (us-east-1). Database backups are kept for fourteen days and are encrypted with the cluster.
Video
Video calls run on a LiveKit server we operate ourselves, on our own machine in our own account. There is no video vendor in the middle: media is encrypted in transit between the browser and that server, and the server holds nothing at rest.
Who can see what
Roles are checked on the server, not hidden in the interface. A patient can only ever read their own record. A clinician without a practice-wide role sees the patients assigned to them and no one else. Asking for a record you are not entitled to returns a plain not-found, never a permission error, because a permission error would confirm that the record exists.
Access to patient records is logged. Every edit to a chart, note, comment, form assignment, or signed AI draft is written to that patient's audit trail with who did it and when, automatically, with nothing to switch on. Audit rows outlive the things they describe, so deleting a comment does not delete the record that it was deleted.
Sign-in is protected by rate limits that count failed attempts only, per address and per account. A whole clinic behind one office IP can sign in all morning without spending any of the budget, while someone spraying passwords runs out in seconds. Passwords are hashed, never stored, and checked against length, similarity, and common-password rules when set.
Companies that touch your data
This is the whole list, and not every one of them is under a business associate agreement yet.
| Company | What it does | What it receives |
|---|---|---|
| Amazon Web Services | Hosting. Application servers, the database, file storage, queues, backups, and the video server all run in our AWS account in the United States. | Everything the product stores, including PHI. |
| Anthropic | Drafting the session note from the transcript when a clinician turns AI notes on, and, only if the practice turns on AI session prep (off by default), rephrasing assessment-based talking points on a patient's chart. | Session transcript text, excerpts of that patient's last three signed notes, their assessment scores and visit cadence, and samples of the clinician's own writing. No name, date of birth, address, or contact details are added by us, though names spoken in a session are in the transcript. |
| Twilio | Sending SMS reminders, confirmations, verification codes, and workflow messages, and receiving patients' text replies. | The recipient's mobile number and the message text: practice name, clinician name, appointment time, and a link. Our templates leave out diagnoses, form names, message bodies, and scores; a practice can add one line of its own to workflow messages. Replies a patient texts back pass through Twilio as written. |
| SendGrid (Twilio) | Sending email: invitations, reminders, password links, receipts. | The recipient's email address and name, plus the same pared-back message text as SMS: practice name, clinician name, appointment time, and a link back into the app. Staff alert emails can carry a short note a practice admin wrote into a workflow. |
| Stripe | Card payments, stored cards for session charges, and payouts. | The payer's name and email, and the card itself, which goes from the patient's browser to Stripe. We never receive or store a card number; we keep the brand and the last four digits. |
| Sentry | Error tracking for the application servers and background workers. | Stack traces, the request method and path, and the internal user id. Request bodies, headers, cookies, query strings, IP addresses and local variables are stripped before an error report leaves our servers. Error and log message text is scrubbed too: database and validation errors are reduced to their error type, and emails, phone numbers, dates and ID-like numbers are redacted from other messages. |
| Cloudflare | DNS, and the network edge in front of the app: it terminates HTTPS and passes traffic on to AWS. Also hosts this marketing website. | Traffic between browsers and the app passes through Cloudflare's network, decrypted at the edge and re-encrypted to AWS. Nothing is stored there by us. |
LiveKit is the obvious name missing from that table. Video in Valence runs on LiveKit, but on a server we operate in our own AWS account rather than as a hosted service, so no LiveKit-the-company system receives your media and there is no subprocessor relationship to disclose. It belongs in the same category as Postgres: software we run, not a vendor we send data to.
We will tell practices before adding a company to this list.
Business Associate Agreement
We sign a BAA with every practice. There is no minimum plan, no fee, and no call to book first. Inside the app it sits under Practice Settings, already filled in with your practice's name and the date you started, ready to download as a PDF.
If you want to read it before you create an account, the same template is published here in full.
What we are not
Valence is not SOC 2 certified. No auditor has examined our controls and there is no report to send you. Some practices need one, and for those practices we are the wrong choice right now. Saying so costs us a few deals and is still cheaper than saying anything else.
We also do not offer multi-factor authentication, and we are a small team, which means the person answering a security question is the person who wrote the code. Depending on what you are weighing, that reads as either the good news or the bad news.
Reporting a vulnerability
Email [email protected]. Tell us what you found and how to reproduce it. A person reads every one of these, and we will write back to confirm we have it and again when it is fixed.
Please do not test against a live practice, and do not use real patient data in a proof of concept. If you need an account to demonstrate something, ask and we will set one up.
We do not run a paid bug bounty. We do credit people who report things properly, if they want the credit.
Common questions
- Does session audio go to a speech-to-text vendor?
- No. Transcription runs in our own worker process using a local Whisper model. There is no third-party speech API in the path and no API key for one, because there is nothing to call.
- How long do you keep session audio?
- The audio is deleted as soon as the draft note is produced, by the same worker that writes the draft. A storage rule removes anything still in the bucket after three days, which covers a run that failed before it got to a draft.
- Is Valence SOC 2 certified?
- No. We are not SOC 2 certified. If that is a requirement for your practice, we are not the right fit yet, and we would rather you know that now than three months in.
- Will you sign a BAA?
- Yes, with every practice, at no cost and without a sales call. You can read the full template at valencebh.com/security/baa before you sign up, and download a copy filled in with your practice name from Practice Settings once you are in.
- Can another practice see my patients?
- Each practice gets its own Postgres schema. Queries run inside one schema, so there is no shared patients table with an organization column that a bad filter could leak across. Nothing in the application can address another practice's schema.
- Do you train AI models on patient data?
- No. Transcripts and notes are used to draft that practice's own notes and nothing else. We do not train models on them and we do not sell or share the data.