Security
Patient data is the most sensitive data a healthcare organisation holds. These are the controls we operate, consolidated in one place for security and procurement review.
Controls
Patient data processed through our platform is hosted entirely in Singapore and is not transferred out of the country in the ordinary course of providing the service.
Data is encrypted in transit and at rest.
Role-based access control on a least-privilege basis. Agent access is scoped to the operations the function requires — booking and routing — and no further.
A dedicated, logically isolated database is provisioned for every organisation. Data from one customer is never commingled with another’s.
Access to systems holding customer data is logged and monitored.
Defined procedures for detecting, containing and reporting incidents. Where a breach is likely to result in significant harm or is of significant scale, we notify the PDPC and affected parties as the PDPA requires, and support customers with their own notification obligations.
Data is retained for the period set out in the customer agreement, and returned or deleted on termination in accordance with it.
Aligned with the MOH/HSA Artificial Intelligence in Healthcare Guidelines (AIHGle 2.0). Agents perform reception and administrative functions only — they do not triage, diagnose or provide clinical advice — with human-in-the-loop controls and monitoring of agent behaviour under test.
Infrastructure, telephony and messaging providers act on our instructions under written confidentiality and data protection obligations. A current subprocessor list is available to customers on request.
Documentation
Get started
A 20-minute walkthrough, tailored to your organisation.
Talk to founders