Security

Security and trust.

Patient data is the most sensitive data a healthcare organisation holds. These are the controls we operate, consolidated in one place for security and procurement review.

Controls

How we protect data.

Data residency

Patient data processed through our platform is hosted entirely in Singapore and is not transferred out of the country in the ordinary course of providing the service.

Encryption

Data is encrypted in transit and at rest.

Access controls

Role-based access control on a least-privilege basis. Agent access is scoped to the operations the function requires — booking and routing — and no further.

Tenant isolation

A dedicated, logically isolated database is provisioned for every organisation. Data from one customer is never commingled with another’s.

Audit logging

Access to systems holding customer data is logged and monitored.

Incident response

Defined procedures for detecting, containing and reporting incidents. Where a breach is likely to result in significant harm or is of significant scale, we notify the PDPC and affected parties as the PDPA requires, and support customers with their own notification obligations.

Data retention

Data is retained for the period set out in the customer agreement, and returned or deleted on termination in accordance with it.

AI governance

Aligned with the MOH/HSA Artificial Intelligence in Healthcare Guidelines (AIHGle 2.0). Agents perform reception and administrative functions only — they do not triage, diagnose or provide clinical advice — with human-in-the-loop controls and monitoring of agent behaviour under test.

Subprocessors

Infrastructure, telephony and messaging providers act on our instructions under written confidentiality and data protection obligations. A current subprocessor list is available to customers on request.

Documentation

For procurement and security review.

Get started

See what we have built.

A 20-minute walkthrough, tailored to your organisation.

Talk to founders