Back to home

Security

Draft under legal review · July 2026

1. Encryption

All communication between your browser and the platform is encrypted (TLS). Patient intake forms are also encrypted at rest (AES-256-GCM) before being stored in the database.

2. Access control

Access to each patient's data is restricted by database-level rules (Row Level Security): a therapist can only see patients they have an active connection with, and only authorized staff of a center can see that center's patients.

3. Authentication

Passwords are never stored in plain text — they are processed through Supabase's authentication system. Sessions are securely shared between sanemos.ai and sanemos-pro via domain-restricted cookies.

4. Verified integrations

Automations that communicate with the platform (for example, sending transactional emails) verify the cryptographic signature of every request before processing it, to prevent forged requests.

5. Providers

We work with a limited number of providers (Supabase, Vercel, Flow, LiveKit, Resend, and an AI provider per the active configuration), all under confidentiality obligations. Full detail is in our Privacy Policy and DPA.

6. Artificial Intelligence

AI-generated summaries and aids are processed only at the therapist's request. We do not use your patients' clinical data to train third-party models.

7. Incident notification

If we detect a security breach affecting your data or your patients' data, we will notify you without undue delay, with a target of 72 hours from becoming aware of it.

8. Report a vulnerability

If you found a security issue, write to us at contacto@sanemos.ai — we'll review it with priority.