Built for regulated industries

Rinovo AI handles protected health information, financial data, and customer conversations for dental, medical, legal, and home-services businesses. Security, privacy, and compliance are core product requirements — not afterthoughts.

Business Associate Agreements

HIPAA

We sign Business Associate Agreements (BAAs) with all business customers in regulated verticals — dental, medical, chiropractic, veterinary, and any other covered entity or business associate that processes PHI through Rinovo.

Our infrastructure stack (Supabase, Vapi AI, Twilio, AWS) maintains BAAs that flow down to cover subprocessor handling of PHI. To request a BAA, email info@myrasolutionsllc.com and we will send a counter-signed copy within one business day.

At rest and in transit

Encryption

All customer data is encrypted at rest using AES-256 on managed Postgres (Supabase) and object storage. All traffic between your browser, our APIs, our subprocessors, and telephony providers is encrypted in transit using TLS 1.3.

Call recordings and transcripts are stored in encrypted buckets with time-limited signed URLs — they are never served from a publicly readable endpoint. Database backups are encrypted with a separate rotating key.

What we have, what's next

Compliance roadmap

  • HIPAA-ready today. BAA available on request; technical and administrative safeguards in place.
  • SOC 2 Type I in progress. Audit scheduled; report targeted for Q3 2026.
  • GDPR available on request. Standard Contractual Clauses and Data Processing Addendums executed for EU-based customers.

Where your data lives

Data residency

All customer data is stored in the US-East AWS region via Supabase. Call audio, transcripts, appointments, and every other customer record stays in the United States. We do not replicate data outside the US.

Role-based access + audit

Access controls

Every Rinovo business supports four roles: owner, admin, manager, receptionist. Permissions are enforced at the database layer via row-level security, not just the UI — so a compromised front-end session cannot escalate privileges.

Every privileged action (staff invitation, agent configuration change, appointment override, data export) is written to an immutable audit log with actor, IP, and user-agent. Customers can request their audit log export at any time.

Who we work with

Subprocessors

These vendors help us deliver the service. Each has been vetted for HIPAA compliance where applicable and has a signed agreement covering data handling.

Supabase

Privacy

Primary database + authentication (US-East)

Vapi AI

Privacy

Voice agent infrastructure (speech-to-text, LLM, text-to-speech)

Twilio

Privacy

Telephony and SMS delivery

AWS SNS

Privacy

Backup SMS delivery + transactional alerts

Stripe

Privacy

Payment processing

Resend

Privacy

Transactional email delivery

Report a vulnerability

Security contact

Please report suspected vulnerabilities, security concerns, or abuse directly to our security team at security@myrasolutionsllc.com. We acknowledge reports within one business day. We do not currently operate a paid bug-bounty program but we will credit responsible researchers on request.

For privacy, data-access, or deletion requests, see our Privacy Policy.