Loading this page
Loading this page
Vantra can sit inside patient communication, clinical monitoring and hospital operations. This page states what is protected today, which controls are deployment-scoped, which third parties may process data, and where contractual readiness still has gaps. If a claim names a mechanism, that mechanism exists in the product today; it is not a certification claim.
Last reviewed 15 July 2026
Where personal data lives, and how it is protected at each layer. We state exactly what is field-encrypted rather than making a blanket claim.
Browser, API and supported vendor-service connections use encrypted transport. Public telephone networks are not represented as end-to-end TLS.
How: HTTPS-only application hosting plus TLS connections to Google Cloud Firestore and configured subprocessor APIs; telephony transport follows the enabled carrier and SIP configuration.
Patient-identifying fields in caller memory, conversations and archives, call logs, Sentinel vitals and Hospital Core clinical records are application-field-encrypted. Scribe consultation data currently relies on infrastructure encryption and server-only access, so we do not describe every store as field-encrypted.
How: AES-256-GCM envelopes (phi:v1) on named stores, boot-time key checks, server-only Firestore rules and Google Cloud infrastructure encryption.
Application policy prohibits full phone numbers and message bodies in operational logs. Logging paths use redaction to a dialing prefix and last two digits, with a keyed one-way token when correlation is needed.
How: Central log-redaction helpers (redaction + keyed HMAC-SHA256 correlation tokens), code-review rules and PHI-free operations-alert payloads.
Clinic and facility data is tenant-scoped. The primary authenticated surfaces check the caller and clinic or facility role server-side; older surfaces that still use narrower legacy guards are tracked as migration debt.
How: Default-deny Firestore rules plus principal, membership and capability checks on clinic, Sentinel, public-API and Hospital Core routes.
You should not have to take our word for what happened in your tenant.
Privileged and sensitive actions are written to a per-tenant audit log where every entry is hash-chained to the previous one — altering or deleting a historical entry breaks the chain and is detectable.
How: Per-tenant SHA-256 hash chain with transactionally-advanced chain heads and a verification endpoint that re-walks the chain.
Data exports (patient subject-access exports, audit-log exports) are themselves audited before the data leaves — if the audit entry cannot be written, the export does not happen.
How: Strict audit writes precede every export response; the export endpoint returns an error when the audit write fails.
Governed data changes carry who did it, through which channel, and what changed — an append-only event ledger alongside the data itself.
How: Append-only entity-events ledger recording actor, source channel, field changes and trace links for governed mutations.
Clinic managers can export their own tenant's audit log — including the chain hashes and an integrity verification result — for retention or external audit.
How: Self-service export endpoint (manager-and-above) returning chained rows plus the chain-verification verdict, itself audited fail-closed.
The agent works inside guardrails; it does not improvise on safety.
Messages that look like emergencies short-circuit the assistant and surface emergency guidance. When the emergency classifier cannot decide, it treats the case as unresolved rather than clear.
How: Deterministic pre-LLM emergency gates plus an LLM classifier whose failure mode appends emergency guidance instead of clearing the case.
A person who opts out of calls is suppressed at the task level — an opted-out contact is never re-queued by any automated campaign, regardless of how old the opt-out is.
How: Suppression records checked by every automated enqueue path (reactivation, waitlist offers, reminders, revenue calls).
Automated calls respect per-clinic calling windows, daily caps, per-purpose cooldowns, and a global kill switch. Money-spending paths are rate-limited with limits that fail closed.
How: Distributed (cross-instance) rate limiting with fail-closed semantics on dialing paths; per-clinic cadence policies; an operator kill switch read at call time.
Prompt, tool and model changes are covered by deterministic and credential-backed golden scenarios, including emergency, booking and prompt-injection cases. A clinic's live Trust Report shows the latest recorded attestation rather than assuming a green result.
How: CI eval harness plus durable eval attestations surfaced by the manager-only live Trust Report.
Autonomy is explicit, scoped and inspectable; some controls are enabled per deployment.
Managers can put booking in propose mode or allow configured automatic booking. Outbound autonomy is currently visible as off or auto; a propose mode for outbound work is not presented as shipped.
How: The manager autonomy control writes through to the same booking-mode configuration used at execution time.
Where the action-policy feature is enabled, configured machine actions can pause in a manager queue. Approval replays the original validated action through the same authorization path rather than bypassing it.
How: Action policies, staged_actions and the governed staged.decide action; dark by default and action-specific.
Where enabled, clinic managers can inspect the gates, allow-listed tool arguments and final reply behind an agent turn. Unknown tool fields are removed fail-closed from the view.
How: Manager-only decision-lineage endpoint and PHI-safe projection, gated by decision_lineage_enabled.
Clinic managers can view current evidence for the latest eval attestation, their audit-chain verification and outcome reconciliation. Missing or partial evidence is shown as such.
How: Manager-only Trust Report assembled at request time from eval_runs, audit-chain verification and outcome_reconciliations.
Vantra staff access grants can carry a named purpose, tenant scope, rationale and expiry. Field-level purpose enforcement is not universal yet, and legacy full-access paths remain explicitly labelled as debt.
How: Purpose registry and expiring purpose_grants with audited grant/revoke operations; progressive policy enforcement.
Sentinel-enabled managers can replay a bounded historical observation window against alternate NEWS2 settings. Stored results contain aggregate counts rather than encounter-level PHI.
How: Rate-limited Sentinel scenario route, governed scenario.run action and counts-only scenario_runs records.
Retention is enforced by a daily job, not by policy documents alone. Clinical-record retention is deliberately a per-clinic policy decision — many jurisdictions require multi-year retention — so it is configurable rather than hard-coded.
Operational data ages out automatically on a daily schedule with per-category windows.
How: A daily data-retention cron with bounded deletes; webhook dedup and rate-limit records also expire via TTL fields.
The current audited export covers the Concierge-linked patient record, lead timeline, caller memory, appointments and staff notes. Scribe, Sentinel and Hospital Core data must currently be assembled through the deployment-specific request process; we do not present the single export as universal. Deletion remains subject to the clinic's legal retention obligations.
How: Fail-closed audited Concierge subject-access export; product-specific retrieval and deletion coordinated with the clinic as controller of record.
| Data | Retention |
|---|---|
| Webhook replay-protection records | Expire automatically (TTL) — hours to days |
| Rate-limit counters | Expire automatically (TTL) — hours |
| Website-demo logs | Deleted after 30 days |
| Error diagnostics | Deleted after 90 days |
| Dead-letter queue entries | Deleted after 30 days |
| Agent turn telemetry | Expires after 90 days |
| Call logs & archived conversations (clinical records) | Retained per the clinic's own policy — configurable window, off by default because medical-record law often requires 6–10 years |
| Sentinel vitals, alerts, orders & encounters | Per-clinic configurable window; automated deletion is off until the deployment sets its clinical-record policy |
| Hospital Core clinical & financial records | Defined per deployment and applicable record law; no blanket short default is asserted |
Third parties that may process data on Vantra's behalf. Some are optional and only apply when a deployment enables that channel, voice provider, calendar or connector. The executed agreement must reflect the services selected for that customer.
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud / Firebase | Database, authentication, file storage | US / EU (region-configurable) |
| Vercel | Application hosting, scheduled jobs, operational logs | US / EU |
| Twilio | Telephony and WhatsApp transport | US |
| Meta Platforms | WhatsApp Cloud API, Instagram, Messenger | US / EU |
| OpenAI | Language models, call transcription | US |
| LiveKit | Realtime voice infrastructure (SIP) | US / EU |
| Cartesia | Text-to-speech voices | US |
| ElevenLabs | Text-to-speech voices | US |
| Soniox | Speech recognition / text-to-speech | US |
| Google Calendar | Appointment calendars (when the clinic connects one) | US / EU |
| eCare CHMIS | Patient and appointment exchange for deployments using the eCare adapter | Deployment-specific |
| Cliniko / Open Dental | Private-validation clinic-system connectors; only when explicitly enabled | Deployment-specific |
| Stripe | Subscription billing; optional patient payment links run on the clinic's own Stripe account | US |
| Resend | Transactional email | US |
Draft template — customer-specific review and execution required
A counsel-review template covers instructions, confidentiality, security measures, sub-processors, data-subject rights, breach notification and deletion. The final jurisdiction, annexes and vendor flow-downs must be reviewed for each deployment.
Not ready for execution — zero BAAs executed
A draft exists for US covered entities, but upstream vendor BAAs, administrative safeguards and open channel decisions are not complete. Vantra has executed zero clinic BAAs and is not currently ready to sign one.
Draft template — local legal review required
For clinics running outbound campaigns: warranties on consent basis and list provenance, suppression-list handling, and the agent's self-identification on calls (modelled on the Turkish İYS regime, adaptable per market).
To request any of these, a security questionnaire response, or a walkthrough of the audit verification, write to info@vantra.xyz.
This page describes product mechanisms, not legal advice. Where a jurisdiction requires specific terms (GDPR, UK GDPR, KVKK, HIPAA), the signed agreement for your clinic is the authoritative document.