Security & privacy

How Vitta protects health data.

We describe only controls that exist in the product today. We do not hold — and therefore do not claim — certifications such as ISO 27001.

Isolation between clinics
All domain data carries the clinic identifier and is protected by row-level security (RLS) in PostgreSQL. The application runs with a database role that has no migration privileges.
LGPD (Brazil’s data protection law)
Data-subject requests (access/portability, correction, deletion, anonymization) with protocol numbers and an event trail; privacy artifacts expire and are purged automatically.
Authentication
Role-based access (front desk, professional, manager). Two-factor authentication via authenticator app (TOTP) is available, enabled per user.
AI control
The AI can only run commands from a closed set, validated by a state machine. Actions with external effect use an operation key and lock so they never repeat. Global switch plus per-conversation override.
Attachments & media
Received files are antivirus-scanned before being made available.
Logging
Sensitive data is redacted in application logs.
Channel
WhatsApp Business Platform, Meta’s official API, with number onboarding through the official flow.
Operations
Metrics, proactive alerts, backups and documented recovery procedures.

What we do not claim yet

  • Formal certifications (ISO 27001, SOC 2): we do not hold any.
  • Mandatory MFA for everyone: today it is optional per user.
  • Average customer results: we are collecting them in pilots, with consent.

Legal documents and contact

Privacy policy, terms and data deletion: privacy · terms · data deletion. Questions or security reports: josuesantos@orbyvitta.com.

← Back to Vitta