Built for regulated industries
Rinovo AI handles protected health information, financial data, and customer conversations for dental, medical, legal, and home-services businesses. Security, privacy, and compliance are core product requirements — not afterthoughts.
Business Associate Agreements
HIPAA
We sign Business Associate Agreements (BAAs) with all business customers in regulated verticals — dental, medical, chiropractic, veterinary, and any other covered entity or business associate that processes PHI through Rinovo.
Our infrastructure stack (Supabase, Vapi AI, Twilio, AWS) maintains BAAs that flow down to cover subprocessor handling of PHI. To request a BAA, email info@myrasolutionsllc.com and we will send a counter-signed copy within one business day.
At rest and in transit
Encryption
All customer data is encrypted at rest using AES-256 on managed Postgres (Supabase) and object storage. All traffic between your browser, our APIs, our subprocessors, and telephony providers is encrypted in transit using TLS 1.3.
Call recordings and transcripts are stored in encrypted buckets with time-limited signed URLs — they are never served from a publicly readable endpoint. Database backups are encrypted with a separate rotating key.
What we have, what's next
Compliance roadmap
- HIPAA-ready today. BAA available on request; technical and administrative safeguards in place.
- SOC 2 Type I in progress. Audit scheduled; report targeted for Q3 2026.
- GDPR available on request. Standard Contractual Clauses and Data Processing Addendums executed for EU-based customers.
Where your data lives
Data residency
All customer data is stored in the US-East AWS region via Supabase. Call audio, transcripts, appointments, and every other customer record stays in the United States. We do not replicate data outside the US.
Role-based access + audit
Access controls
Every Rinovo business supports four roles: owner, admin, manager, receptionist. Permissions are enforced at the database layer via row-level security, not just the UI — so a compromised front-end session cannot escalate privileges.
Every privileged action (staff invitation, agent configuration change, appointment override, data export) is written to an immutable audit log with actor, IP, and user-agent. Customers can request their audit log export at any time.
Who we work with
Subprocessors
These vendors help us deliver the service. Each has been vetted for HIPAA compliance where applicable and has a signed agreement covering data handling.
Supabase
PrivacyPrimary database + authentication (US-East)
Vapi AI
PrivacyVoice agent infrastructure (speech-to-text, LLM, text-to-speech)
Twilio
PrivacyTelephony and SMS delivery
AWS SNS
PrivacyBackup SMS delivery + transactional alerts
Stripe
PrivacyPayment processing
Resend
PrivacyTransactional email delivery
Report a vulnerability
Security contact
Please report suspected vulnerabilities, security concerns, or abuse directly to our security team at security@myrasolutionsllc.com. We acknowledge reports within one business day. We do not currently operate a paid bug-bounty program but we will credit responsible researchers on request.
For privacy, data-access, or deletion requests, see our Privacy Policy.