---
title: Security and compliance | Nextvisit
description: HIPAA, SOC 2 Type II, and AI governance practices. We do not train AI on PHI. Nextvisit trains AI on other customer data by default, and customers can opt out.
url: "http://localhost:3000/security"
type: static
generatedAt: "2026-09-04T06:57:03.093Z"
---

Security and compliance
# Mental health data requires more than standard security controls.

Security combines independent audits, BAAs, encryption, and documented AI controls.
           HIPAA Compliant     SOC 2 Type II     BAA Available by default           AI governance
## How we govern AI over time.

We monitor model behavior, review risks, and improve controls over time.
     How we handle data
## Clear PHI boundaries.

 - Encrypted in transit and at rest (TLS 1.3, AES-256).
- We do not train AI on PHI. Nextvisit trains AI on other customer data by default, and customers can opt out.
- Configurable retention. Recordings deleted on signature.
- SSO, SCIM provisioning, audit logs.
- US-hosted on infrastructure with HIPAA BAAs.
            Responsible AI
### The clinician is always the author.

AriaMD is grounded in retrieved encounter context, uses safety guardrails, and surfaces sources for every assessment. The clinician reviews and signs. The AI never owns the chart.
   [Open the trust center](https://trust.nextvisit.ai) [security@nextvisit.ai](mailto:security@nextvisit.ai)