Security & privacy
How Vitta protects health data.
We describe only controls that exist in the product today. We do not hold — and therefore do not claim — certifications such as ISO 27001.
- Isolation between clinics
- All domain data carries the clinic identifier and is protected by row-level security (RLS) in PostgreSQL. The application runs with a database role that has no migration privileges.
- LGPD (Brazil’s data protection law)
- Data-subject requests (access/portability, correction, deletion, anonymization) with protocol numbers and an event trail; privacy artifacts expire and are purged automatically.
- Authentication
- Role-based access (front desk, professional, manager). Two-factor authentication via authenticator app (TOTP) is available, enabled per user.
- AI control
- The AI can only run commands from a closed set, validated by a state machine. Actions with external effect use an operation key and lock so they never repeat. Global switch plus per-conversation override.
- Attachments & media
- Received files are antivirus-scanned before being made available.
- Logging
- Sensitive data is redacted in application logs.
- Channel
- WhatsApp Business Platform, Meta’s official API, with number onboarding through the official flow.
- Operations
- Metrics, proactive alerts, backups and documented recovery procedures.
What we do not claim yet
- Formal certifications (ISO 27001, SOC 2): we do not hold any.
- Mandatory MFA for everyone: today it is optional per user.
- Average customer results: we are collecting them in pilots, with consent.
Legal documents and contact
Privacy policy, terms and data deletion: privacy · terms · data deletion. Questions or security reports: josuesantos@orbyvitta.com.