Skip to content

Compliance center

Security you can read, not just a badge.

Terra is HIPAA compliant and SOC 2 compliant. This page explains what that covers, how patient information is protected, who processes it, and how the AI stays under a clinician's control.

HIPAA and SOC 2

HIPAA compliant

Terra acts as your business associate

  • Administrative, physical and technical safeguards under the HIPAA Security Rule
  • HIPAA training for everyone on the Terra team
  • A Business Associate Agreement with every paid customer
  • BAAs with every subprocessor that handles PHI
  • Breach notification procedures and incident response

HIPAA has no official certification. We describe our program as compliance, never certification.

SOC 2 compliant

Independently examined controls

Report type
{{SOC2_TYPE}}
Period covered
{{SOC2_PERIOD}}
Auditor
{{AUDITOR}}
Availability
On request, under NDA
Request the report

Security practices

How patient information is protected

These are the controls in the product today. They are described in more depth in our Help Center articles on sessions, roles and patient access.

Encryption in transit

Every connection to Terra, our APIs and our subprocessors uses TLS. Session cookies are Secure, HttpOnly and SameSite=Strict.

Encryption at rest

Databases, private file storage and backups are encrypted at rest by our cloud providers. Recordings and documents are served only through authenticated, access-checked requests.

Signed, short-lived sessions

Access tokens are Ed25519-signed and last 15 minutes. Refresh tokens rotate on every use; replaying an old one ends the session. Users can see and end their sessions.

Hashed credentials

Passwords are stored as bcrypt (cost 12) of a SHA-256 pre-hash. Refresh, invitation and email tokens are stored only as SHA-256 hashes. Failed sign-ins look identical and are rate limited.

Roles and patient access

Clinician, assistant and administrator roles, a separate management permission, and per-patient restriction to named people or care teams. Every request checks the current membership.

Audit history

Workspace and identity actions are recorded with actor and time. Managers can filter them and export a verified JSON snapshot with a SHA-256 checksum.

Signed-note integrity

A signed note is frozen with a SHA-256 hash. Changes become dated, attributed amendments; co-signatures attest to a frozen copy. Exports are checked against their hash before download.

Retention controls

Practices set a raw-audio retention policy (1 to 3,650 days after clinician review) with a recovery window and legal hold, and can retire original document files after review. Transcripts and signed notes are kept.

Least data to providers

AI requests send only the sources the clinician sees in the quote, with provider storage disabled and no tools. The encounter header omits name, MRN and date of birth. Provider errors are never shown or logged.

Subprocessors

Who processes data for Terra

Every subprocessor that handles PHI is bound by a business associate agreement with Terra. We will update this list, and notify customers by email, before adding a subprocessor that handles PHI.

Terra subprocessors
SubprocessorPurposeDataRegion
Google CloudPHI · BAAApplication hosting (Cloud Run), private file storage, secrets, background tasks, and Gemini models for drafting, record chat and summariesAll application data, including PHI, encrypted at restUnited States (us-central1)
OpenAIPHI · BAAAI models for note drafts, record chat, coding suggestions, evidence answers and recorded-file transcriptionThe sources shown in each request's quote; never patient name, MRN or date of birth in the encounter headerUnited States
AssemblyAIPHI · BAALive speech recognition during a visitMicrophone audio streamed during a live session and the resulting text; Terra stores no live audioUnited States
MongoDB AtlasPHI · BAAManaged database for workspace and account recordsApplication records, including PHI, encrypted at restUnited States
StripeNo PHISubscriptions, top-ups, invoices and the billing portalBilling contact, plan and payment details; opaque practice references only, no patient dataUnited States
Google WorkspaceNo PHIAccount email: verification, password reset and welcome messagesUser name and email address; no patient dataUnited States
NetlifyNo PHIHosting for the useterra.si website and its contact formWebsite request logs and contact-form messages; no patient dataGlobal edge network, United States origin

Evidence research also sends de-identified search queries that a clinician has approved to public services: NCBI (PubMed and PubMed Central), DailyMed, openFDA and MedlinePlus. These are not subprocessors: they receive no patient information, account details, cookies or identity from Terra.

Last updated October 2, 2026.

Responsible AI

The clinician decides. The AI shows its work.

Terra uses large language and speech models from Google (Gemini), OpenAI and AssemblyAI. These are the commitments that govern how they are used.

A clinician reviews everything

Drafts, transcripts, code suggestions, chat answers and evidence summaries are proposals. Nothing is signed, approved, submitted or sent to a patient without a clinician's explicit action.

Every claim has a source

Draft sections cite the transcript or chart source they came from. Chat answers cite exact record excerpts. Evidence answers cite retrieved passages only. An unsupported section reads [Not documented].

No autonomous actions

Terra's AI cannot place orders, message patients, submit claims or change the chart. It never upgrades a possible diagnosis to confirmed and never treats a missing allergy as no known allergies.

History is labelled as history

Prior notes and problem lists are marked historical, not today's findings. If a chart source changes while a draft runs, the draft is discarded rather than applied.

Terra is a documentation tool, not a medical device. It does not diagnose, recommend treatment or determine billing. We do not publish accuracy or time-saved figures until they come from a documented evaluation.

Business Associate Agreement

Sign a BAA before your first real patient.

Terra signs a BAA with every practice on a paid plan, at no extra cost. Email us from the practice manager's address with your practice's legal name, address and signer, and we send the agreement for electronic signature, usually within two business days.

  1. 1Request the BAA by email
  2. 2Sign it electronically
  3. 3Choose a paid plan
  4. 4Start documenting real visits

Vulnerability disclosure

Found a security issue? Tell us.

We welcome reports from researchers and customers. Email security@useterra.si with a description, the affected URL or feature, and steps to reproduce.

What we commit to

  • Acknowledge your report within two business days.
  • Keep you updated until it is fixed.
  • Credit you, if you wish, once it is resolved.
  • Not pursue legal action for good-faith research within these rules.

What we ask

  • Test only with accounts you own and synthetic data.
  • Never access, change or keep another customer's data or any PHI.
  • No denial-of-service, spam or social engineering.
  • Give us reasonable time to fix before disclosing.

Questions

Compliance questions