AI disclaimer: Kevin! supports clinical documentation workflows only — it does not provide medical advice, diagnosis, or treatment. All outputs require review by a licensed clinician. Learn more
Skip to main content
Back to KevinSecurity

Security and data handling.

Kevin! is designed for clinical documentation workflows with signed BAAs for AI processing, confidential handling of PHI, encryption in transit and at rest, and required clinician review. This page summarizes the controls used for procurement and security review.

BAA-covered processing

AI processing runs through signed Business Associate Agreements with Google and OpenAI. Covered inputs are not used to train general-purpose models.

Encryption

Data is protected with TLS 1.2+ in transit and AES-256 encryption for stored data on our side.

Clinician oversight

Kevin drafts the work; a licensed clinician reviews and approves every output before it is used clinically.

Our commitments

  • Signed BAAs with Google and OpenAI for AI processing
  • Runs on SOC 2 Type II–audited, BAA-covered infrastructure
  • PHI and clinical inputs are kept confidential and are not sold
  • Covered AI inputs are not used to train general-purpose models
  • TLS 1.2+ in transit and AES-256 encryption for stored data on our side
  • Licensed clinician review remains required before clinical use

Built on

Google Cloud RunFirebaseVertex AI (Gemini)OpenAI

Each provider maintains its own SOC 2 Type II attestation. AI processing runs under signed Business Associate Agreements where PHI is handled.

Need security documentation, a subprocessor list, or procurement details? Contact our team and we'll walk you through it.