Trust
Security and compliance.
Vytivo holds the certifications, runs the controls, and signs the agreements for every product it operates. PracticeHQ and Vytivo Connect share the same controls.
Uptime target
99.9%
Recovery time
4hours
Recovery point
1hour
Security logs retained
365days
Certifications.
Reports and policies are available in the trust center on request.
End-to-end encryption. At rest and in transit.
Full audit logging. Every PHI access, recorded.
Two-factor authentication. Required for every account.
Customers own their data. Full export, on request.
Operating commitments.
What we commit to in production, across every product.
01
Availability
99.9% monthly uptime target for every product, with service credits available in enterprise agreements. Status and incident history are published in the trust center.
02
Resilience
Recovery time objective of 4 hours and recovery point objective of 1 hour. Daily encrypted snapshots, restore drills, and restricted on-call access to backups.
03
Data residency
Data is stored in the United States by default, with regional hosting available where a contract requires it. Subprocessors are listed and versioned.
04
AI governance
An ISO 42001 certified management system. Models are not trained on identifiable health data. AI actions require approval before they take effect.
Customers own their data.
Full export in standard FHIR and bulk formats on request. Deletion on termination, subject to legal retention requirements. Application logs are kept 30 days, security event logs 365 days, and export artifacts 7 days.
Incident response.
Critical incidents are handled around the clock: 1-hour response for severity 1, same-day for severity 2. Customers affected by a confirmed breach are notified within the timelines their agreement and applicable law require.
Documents and policies.
Questions for our security team?
Security questionnaires, audit reports under NDA, and BAA requests go to security@vytivo.com. Privacy requests go to privacy@vytivo.com.