CLINSIA
Security overview
Version 1.0 · July 2026
contact@clinsia.com

Security, privacy and compliance

A reference document for legal, IT and medical leadership teams evaluating Clinsia. It summarizes how clinical information is protected at every stage: capture, processing, storage and transmission.

1. What data does Clinsia process

2. Encryption and technical security

3. Hosting and sub-processors

ItemDetail
Data hostingCloud infrastructure managed by Vercel, with primary hosting in the United States and enterprise-grade security standards.
Data processor sub-processorsVercel (infrastructure and hosting) and AI model providers for transcription and writing, including OpenAI and Anthropic. The complete and current list is detailed in the DPA.
Original audio retentionRetained as long as necessary to ensure service quality and then deleted. The timeframe is configurable by each institution.
Transcription and document retentionRetained while the institution maintains the service. Timelines and deletion policies are configurable by institution.

4. Data ownership and use

5. Patient consent

6. Human oversight

7. Regulatory framework

This document is a commercial reference sheet and does not constitute legal advice. Contractual commitments are formalized in the DPA and service agreement. For an in-depth technical review (architecture, penetration testing, internal policies), we coordinate a session with your systems team: contact@clinsia.com.