PsychDraft LogoPsychDraft
SECURITY & PRIVACY

Security designed around clinical responsibility.

PsychDraft was built for privacy-sensitive neuropsychological workflows. We use HIPAA-eligible infrastructure under active BAAs, minimize unnecessary data retention, and keep clinicians in control of every generated output.

4-page PDF • Version 1.0 • Last updated June 2026

AWS BAA Active
HIPAA-Eligible Infrastructure
Encryption in Transit and at Rest
Clinician-Controlled Review

Clinical information submitted to PsychDraft is processed only to generate the documentation you request. It is not used to train foundation AI models.

KEY SAFEGUARDS

Security at a glance

AWS Business Associate Agreement active
HIPAA-eligible infrastructure
Encryption in transit
Encryption at rest
No foundation model training
Clinician-controlled outputs
Built for neuropsychology workflows

How clinical data moves through PsychDraft

See how clinical information is transmitted, processed, returned, and cleared during a PsychDraft session.

1. Data Input

Clinician

Clinician initiates session and enters observation notes or clinical parameters.

2. In Transit

Encrypted Connection

Encrypted browser connection (TLS 1.3) protects clinical data during transmission.

3. AWS Bedrock

Secure AI Processing

AI processing runs under an active AWS BAA, using secure, private execution environments.

4. To Browser

Draft Returned

Structured clinical draft language is returned directly to the clinician's workspace.

5. Clearance

Session Ends

Temporary clinical content is cleared when the session ends and memory is cleared.

Data is encrypted during transmission using secure TLS protocols, establishing a secure connection directly between the clinician's browser and our AWS deployment.

Processing occurs only to generate the requested clinical draft, operating on a temporary memory execution framework that avoids persistence.

Clinicians retain sole responsibility for reviewing, editing, interpreting, and approving final documentation. PsychDraft is an assistant, not an independent evaluator.

Temporary clinical content is cleared when the session ends, ensuring that clinical inputs and temporary context do not persist on servers once processing finishes.

How we protect your clinical data

Clinically grounded technology demands rigorous data protection rules. We operate under strict transparency.

Encryption

  • TLS 1.3 encryption during all transmission
  • Encrypted cloud infrastructure and network layers
  • Industry-standard AES-256 encryption at rest

Business Associate Agreements

  • AWS Bedrock operates under an active BAA
  • Built entirely on HIPAA-eligible infrastructure
  • Enterprise documentation available upon request

AI Privacy

  • Clinical information is processed only to generate requested drafts
  • Data is not used to train foundation AI models
  • Clinicians remain in control of all documentation

Data Retention

  • Architecture designed to minimize unnecessary storage
  • Temporary workflow context is cleared after sessions
  • Saved reports require explicit clinician action (where applicable)

Infrastructure & Service Providers

To maintain complete transparency for IT departments and compliance officers, here is the list of third-party infrastructure providers used by PsychDraft.

ComponentProvider
AI ProcessingAWS Bedrock
Application HostingVercel
AuthenticationSupabase
PaymentsStripe
Email CommunicationsMailerLite

Security FAQ

Clear, factual answers regarding data handling, system boundaries, and organizational setups.

Our Clinical AI Principles

Our platform is built to align with professional ethics, clinical boundaries, and standard psychology practices. PsychDraft supports documentation. The clinician remains responsible for reviewing, editing, interpreting, and approving all clinical content.

Clinician Directed

PsychDraft assists documentation but does not replace clinical judgment. Clinicians remain responsible for interpretation, diagnosis, recommendations, and final report approval.

Transparent

PsychDraft generates drafts from clinician-provided information rather than independently making clinical decisions.

Privacy First

The platform is designed to minimize data retention and limit processing to what is necessary for the requested workflow.

Built for Neuropsychology

PsychDraft was designed specifically around neuropsychological documentation workflows rather than adapting a generic AI writing assistant.

What remains with the clinician

  • DiagnosisSynthesis & diagnostic code decisions
  • Clinical judgmentEvaluating discrepancies and context
  • Ethical decision-makingPatient relationship & ethical practice rules
  • InterpretationMeaning-making & interpretive synthesis
  • Final review and approvalAbsolute authority and approval of every word

Clinical technology should earn your trust.

Review how PsychDraft works, explore our security documentation, or begin with three free sessions while remaining in control of every output.

Security & Privacy Overview, Version 1.0 — updated June 2026

PsychDraft is built on HIPAA-eligible AWS cloud infrastructure designed to support privacy-sensitive clinical documentation workflows, including secure AI processing through AWS.

Clinicians retain full responsibility for evaluating appropriate use, obtaining patient consents, and ensuring their final documentation aligns with institutional policies, ethics boards, and applicable state or federal regulations.

This information is provided for general transparency and does not constitute legal or regulatory advice. Organizations are responsible for determining whether PsychDraft is appropriate for their compliance requirements and workflows.

Security Documentation • Version 1.0
Last Updated: June 2026