Vet Callora in one click.
Health-system procurement teams, CISOs, and compliance officers: everything you need to greenlight Callora for medical recruiting is on this page. If it isn't, emailsecurity@call.metis.gold— we respond within one business day.
Posture at a glance
BAA available (Callora Business · Medora Locum Pro & Agency)
We sign a mutual Business Associate Agreement before any PHI touches Callora or Medora. Standard OCR-model BAA; redlines welcome. Turnaround: typically 5 business days.
Encryption in transit (TLS 1.3)
All API traffic, WebSocket voice streams (SRTP/DTLS), and telephony bridge (Twilio) enforce TLS 1.3. HSTS + preload on primary domain.
Encryption at rest (AES-256-GCM)
MongoDB Atlas volume encryption plus field-level encryption for phone numbers, DEA numbers, and interview transcripts. Keys rotated quarterly via KMS.
Least-privilege access
RBAC across recruiter / admin / owner roles. Production DB access is break-glass only, MFA-enforced, and logged to an immutable audit chain.
Immutable audit log
Every candidate mutation, credential verification, consent change, and stage transition is hash-chained (SHA-256) and exportable as CSV for auditors.
Tenant isolation
All queries scoped by owner/tenant at the query layer. Zero cross-tenant reads verified via automated integration tests on every deploy.
US data residency
Primary data residency: US-East (Virginia). EU-region option available on Medora Agency (contact sales). No PHI ever leaves the region without explicit written approval.
SOC 2 Type I — in progress
Type I readiness assessment underway with a Big Four-affiliated auditor. Expected: Q3 2026. Type II attestation to follow after 6 months of continuous evidence.
Control families
Access
- MFA required for all human accounts
- SSO (Google Workspace, Okta) on Business tier
- Session tokens rotated every 12 hours
- Break-glass access with 24h auto-expiry
Data
- Field-level encryption on PHI columns
- Daily automated backups (7-day retention on Pro, 30-day on Business)
- Point-in-time restore within retention window
- Right-to-delete: candidate data purged within 30 days on written request
Voice & PHI-in-voice
- Voice call recordings encrypted at rest
- Transcripts stored under BAA scope only when the customer opts in
- Automatic PHI redaction of SSN / DOB / MRN in transcripts (regex + LLM classifier)
- Voice models never trained on customer PHI
Monitoring
- Real-time error tracking (Sentry with PII scrubbing)
- 24/7 uptime + latency monitoring
- Anomalous-access alerts (geographic, off-hours, bulk export)
- Quarterly access reviews
Subprocessors
These are the third-party services in scope of the BAA. Updated when we add or remove any; customers are notified 30 days in advance.
| Vendor | Purpose | BAA / DPA | Region |
|---|---|---|---|
| OpenAI | Voice generation + LLM reasoning | BAA in force (Enterprise agreement) | US |
| Twilio | Telephony (SIP, PSTN) | BAA in force | US |
| MongoDB Atlas | Primary data store | BAA in force | US-East |
| Stripe | Billing (no PHI stored) | N/A — no PHI | US |
| Cloudflare | WAF, CDN, DDoS | BAA in force (Business tier) | Global edge, US origin |
| Resend | Transactional email (no PHI in email body) | DPA in force | US |
| Sentry | Error tracking (PII scrubbed) | DPA in force | US |
FAQ
Incident response commitment
In the event of a security incident involving PHI, we notify affected customers within 24 hours of confirmed compromise, with a full RCA within 5 business days. HIPAA breach notifications (60-day OCR clock) are coordinated with the customer's privacy officer as the Covered Entity.
Responsible disclosure: security@call.metis.gold · PGP key on request · Hall of fame + swag for verified reports.