HIPAA · BAA · Medical

Vet Callora in one click.

Health-system procurement teams, CISOs, and compliance officers: everything you need to greenlight Callora for medical recruiting is on this page. If it isn't, emailsecurity@call.metis.gold— we respond within one business day.

Posture at a glance

BAA available (Callora Business · Medora Locum Pro & Agency)

We sign a mutual Business Associate Agreement before any PHI touches Callora or Medora. Standard OCR-model BAA; redlines welcome. Turnaround: typically 5 business days.

Encryption in transit (TLS 1.3)

All API traffic, WebSocket voice streams (SRTP/DTLS), and telephony bridge (Twilio) enforce TLS 1.3. HSTS + preload on primary domain.

Encryption at rest (AES-256-GCM)

MongoDB Atlas volume encryption plus field-level encryption for phone numbers, DEA numbers, and interview transcripts. Keys rotated quarterly via KMS.

Least-privilege access

RBAC across recruiter / admin / owner roles. Production DB access is break-glass only, MFA-enforced, and logged to an immutable audit chain.

Immutable audit log

Every candidate mutation, credential verification, consent change, and stage transition is hash-chained (SHA-256) and exportable as CSV for auditors.

Tenant isolation

All queries scoped by owner/tenant at the query layer. Zero cross-tenant reads verified via automated integration tests on every deploy.

US data residency

Primary data residency: US-East (Virginia). EU-region option available on Medora Agency (contact sales). No PHI ever leaves the region without explicit written approval.

SOC 2 Type I — in progress

Type I readiness assessment underway with a Big Four-affiliated auditor. Expected: Q3 2026. Type II attestation to follow after 6 months of continuous evidence.

Control families

Access

  • MFA required for all human accounts
  • SSO (Google Workspace, Okta) on Business tier
  • Session tokens rotated every 12 hours
  • Break-glass access with 24h auto-expiry

Data

  • Field-level encryption on PHI columns
  • Daily automated backups (7-day retention on Pro, 30-day on Business)
  • Point-in-time restore within retention window
  • Right-to-delete: candidate data purged within 30 days on written request

Voice & PHI-in-voice

  • Voice call recordings encrypted at rest
  • Transcripts stored under BAA scope only when the customer opts in
  • Automatic PHI redaction of SSN / DOB / MRN in transcripts (regex + LLM classifier)
  • Voice models never trained on customer PHI

Monitoring

  • Real-time error tracking (Sentry with PII scrubbing)
  • 24/7 uptime + latency monitoring
  • Anomalous-access alerts (geographic, off-hours, bulk export)
  • Quarterly access reviews

Subprocessors

These are the third-party services in scope of the BAA. Updated when we add or remove any; customers are notified 30 days in advance.

VendorPurposeBAA / DPARegion
OpenAIVoice generation + LLM reasoningBAA in force (Enterprise agreement)US
TwilioTelephony (SIP, PSTN)BAA in forceUS
MongoDB AtlasPrimary data storeBAA in forceUS-East
StripeBilling (no PHI stored)N/A — no PHIUS
CloudflareWAF, CDN, DDoSBAA in force (Business tier)Global edge, US origin
ResendTransactional email (no PHI in email body)DPA in forceUS
SentryError tracking (PII scrubbed)DPA in forceUS

FAQ

Do you sign a BAA?
Yes — on Callora Business and on both Medora paid tiers (Locum Pro, Agency). Contact security@call.metis.gold to initiate. Our standard is a mutual OCR-model BAA; we accept reasonable redlines.
Is PHI required to use Callora?
No. Callora can be used purely as a top-of-funnel sourcing/outreach tool with only recruiter-supplied contact info (name, phone, NPI). PHI (medical records, patient data) is never required and should not be entered.
What happens to a candidate's data if they revoke consent?
Consent revocation is immediate. All outreach halts, and the candidate is marked Do-Not-Contact. On written request (candidate or recruiter), records are purged within 30 days.
Do you train models on our data?
No. Customer conversations, transcripts, and candidate records are never used to train foundation models. Prompts and voice audio are transient; only what the customer explicitly saves is retained.
Where is data stored?
Primary: US-East (Virginia). Backups: US-East (encrypted). EU-residency available on Enterprise agreements.
Can we get a security questionnaire filled out?
Yes — SIG Core / CAIQ / VSA / HITRUST i1 mapping available on request. Email security@call.metis.gold.

Incident response commitment

In the event of a security incident involving PHI, we notify affected customers within 24 hours of confirmed compromise, with a full RCA within 5 business days. HIPAA breach notifications (60-day OCR clock) are coordinated with the customer's privacy officer as the Covered Entity.

Responsible disclosure: security@call.metis.gold · PGP key on request · Hall of fame + swag for verified reports.

Last updated August 29, 2026
security@call.metis.gold · privacy@call.metis.gold · legal@call.metis.gold