Security

What we actually do, in the order it matters.

Not a badge wall. The specific mechanisms, described plainly enough that your own security reviewer can check them.

01

A separate encryption key for every practice.

Submissions, call recordings, transcripts and appointment details are encrypted with a key belonging to that practice alone. One practice's records cannot be read with another's credentials, and destroying a practice's key makes everything of theirs unreadable in a single act.

02

Access is enforced underneath the query.

Every table carrying patient information has row-level rules applied by the database itself. A query written wrongly returns nothing rather than somebody else's records. That is the difference between a system that is careful and a system that is safe.

03

Nothing is collected before an agreement is in force.

The gate is technical, not procedural. Until the practice's agreement is countersigned the system refuses submissions and refuses calls. The agreements →

04

Every access to patient data is written down.

Who, when, which record, and — for a call recording — the reason they gave for opening it. The audit log cannot be edited or deleted, including by us.

05

Destruction on the practice's own schedule.

Each practice sets its retention period. When it expires, submissions, recordings and transcripts are destroyed — including at the provider that carried the call — and a record that the data existed and was destroyed remains.

06

Where data goes, and where it does not.

Every third party that could receive patient information is listed, with what they receive and whether they have signed an agreement. Anything not on that list is blocked from receiving patient data at all — not discouraged, blocked.

We do not send patient information to advertising or analytics platforms. There is no integration to disable, because there is no integration.

What we do not claim

No certifications. We will not imply otherwise.

Minnato holds no SOC 2, HITRUST or ISO certification today.

We do not sell medical-grade hosting. The practice sites we host are brochureware by design, and patient data is served from a separate encrypted origin.

For voice, processing involves a subprocessor. We will name it and its regions in writing rather than assert a data-residency commitment we have not secured — ask before procurement, not during.

Anything stronger than the mechanisms on this page needs a lawyer, and we would rather send you a straight answer than a badge.

Start by finding out what your websites are leaking.

A free scan of any practice site tells you in ninety seconds which trackers are loading on pages that collect patient information. No account, no card.