Trust Center
How Therapy Companion protects clinical data.
Therapy Companion is the connected operating system for a therapy practice, and the same protections cover every module, from records and scheduling to insurance workflows. HIPAA compliance is verified, not promised.

- ✓ Signed BAAs with all infrastructure providers
- ✓ 38 published HIPAA policies
- ✓ Completed security risk assessment
- ✓ 42 CFR Part 2 (substance-use confidentiality)
How your data is protected
Defense in depth, at every layer of the platform.
AES-256 encryption
Every record is encrypted at rest and in transit.
Revocable sessions
A password reset ends every existing session, and any device can be signed out from account settings.
Row-level security
Data is isolated per therapist-client pairing, enforced at the database. No one else can reach it.
Full audit logging
A complete access trail for every piece of protected health information.
Automatic session timeouts
Idle sessions end automatically to prevent unattended access.
Signed BAAs
Business Associate Agreements in place with every infrastructure provider.
Role-based access
Therapists, supervisors, and practice owners each see only what their role permits.
Permissioned client sharing
Clients see only what their therapist chooses to share. Nothing is visible without permission.
Privacy by design
What Therapy Companion does not do matters as much as what it does.
Therapy Companion never records or listens to sessions. Documentation is drafted from the therapist's own typed notes.
Client data is never sold or shared with advertisers. It belongs to the therapist and the client, full stop.
Practice-record export on demand: client records, session documentation, and appointments, in standard formats. Private psychotherapy notes remain separate under their own protections. No lock-in, before, during, or after the switch.
On the roadmapHITRUST certification is on the Therapy Companion roadmap. It is not yet certified, and no timeline is promised. Two-factor authentication: Authenticator-app codes with backup codes are built and are not yet turned on for accounts. No timeline is promised.
Security questions.
Do you have two-step sign-in verification?
It is built and is not yet turned on for accounts, and no timeline is promised. Revocable sessions are the control in place today: a password reset ends every existing session, and any device can be signed out from account settings.
Questions about security or compliance?
See the live compliance report, or talk it through in a walkthrough covering privacy, BAAs, and onboarding.