Uncompromising Protection of Your Information

At In Therapy, we understand that sharing personal and clinical information requires profound trust. Our security framework is built on defense-in-depth principles, ensuring that your data remains confidential, intact, and accessible only to authorized professionals directly involved in your care.

Enterprise-Grade Security Infrastructure

We employ multiple layers of protection across our entire technology stack, from client browsers to database storage.

๐Ÿ”

End-to-End Encryption

All data in transit is protected via TLS 1.3. Data at rest is encrypted using AES-256 standard encryption with rotating keys managed by hardware security modules.

๐Ÿ›ก๏ธ

Zero-Trust Access Control

Multi-factor authentication, role-based permissions, and least-privilege principles ensure only verified staff access specific data required for your treatment.

โ˜๏ธ

Secure Cloud Infrastructure

Hosted on isolated, audited cloud environments with automated backups, geo-redundant storage, and continuous vulnerability scanning.

๐Ÿ‘๏ธ

24/7 Monitoring & Logging

Real-time threat detection, automated anomaly alerts, and immutable audit logs track every access attempt and system modification.

๐Ÿ”’

Secure Communication Channels

Video, audio, and messaging sessions use HIPAA-compliant WebRTC with end-to-end encryption. No recordings are stored without explicit consent.

๐Ÿงช

Regular Penetration Testing

Independent third-party security firms conduct quarterly penetration tests and annual code audits to identify and remediate vulnerabilities proactively.

Regulatory Compliance & Industry Standards

We adhere to strict legal and industry frameworks to ensure your data is handled lawfully, fairly, and transparently.

HIPAA

HIPAA & HITECH Compliance

Full compliance with U.S. healthcare privacy and security rules, including Business Associate Agreements (BAAs) for all third-party vendors.

GDPR

GDPR & CCPA Alignment

Strict adherence to EU and California data protection laws, ensuring your rights to access, rectify, and erase personal data are fully honored.

SOC2

SOC 2 Type II Certified

Independently audited controls covering security, availability, processing integrity, confidentiality, and privacy of client systems.

ISO

ISO 27001 Ready

Information Security Management System (ISMS) aligned with international best practices for risk assessment and continuous improvement.

How We Handle Your Data

From collection to deletion, every stage of your data's lifecycle is governed by strict protocols designed to minimize risk and maximize control.

Collection

We only collect data necessary for treatment, billing, and safety. Consent is explicit, and you may withdraw it at any time. No third-party trackers or behavioral analytics are used.

Storage & Retention

Clinical records are stored securely for the legally required period (typically 7-10 years post-treatment). After retention periods expire, data is permanently purged using certified wiping standards.

Access & Sharing

Your information is never sold or shared for marketing. Clinical data is only accessible to your direct care team. External sharing requires written consent or legal mandate.

Portability & Deletion

You retain full ownership of your records. Request a complete data export in standard formats, or submit a formal deletion request. We process all requests within 30 days.

๐Ÿšจ Incident Response Protocol

  • 24/7 security operations center monitors for threats
  • Automated containment triggers isolate compromised systems
  • Transparent client notification within 72 hours if required
  • Post-incident forensic analysis and public transparency reports
  • Dedicated breach response team with legal & clinical oversight

๐Ÿ’ก Client Security Best Practices

  • Use strong, unique passwords for your client portal
  • Enable multi-factor authentication on your account
  • Access sessions only on trusted, private networks
  • Log out of shared or public devices immediately
  • Report suspicious emails or phishing attempts promptly

Security Inquiries & Concerns

Have questions about our data practices, need to exercise your privacy rights, or suspect a security issue? Our dedicated privacy team is here to help.

Contact Privacy Team โ†’