Trust Center

Security and privacy at Filo

Filohealth Software, Inc. builds healthcare software, and we hold ourselves to high standards of security practices. This page documents our compliance posture, subprocessors, and data processing agreements.

Compliance

GDPR badge
GDPR
Compliant

EU General Data Protection Regulation. Customer data is hosted in the EU/UK, and Standard Contractual Clauses are incorporated into our Data Processing Agreement.

HIPAA badge
HIPAA
Compliant

Administrative, physical, and technical safeguards for protected health information. BAAs available for covered entities.

Security practices

Encryption everywhere
All data is encrypted in transit with TLS 1.2+ and at rest with AES-256.
EU/UK data residency
Customer data is hosted in the EU and UK; the only US-based subprocessor is our payment provider (Stripe) which we have a DPA with.
Access control
Role-based access, SSO enforcement, and least-privilege reviews every quarter.
Vendor management
Every subprocessor is risk-assessed and bound by a DPA or BAA before use.
Incident response
Documented IR plan with customer notification within 72 hours of a confirmed breach.
Business continuity
Daily encrypted backups, tested restores, and redundant infrastructure.

Subprocessors

Third parties that process customer data on our behalf. Full details — locations, data categories, and safeguards — require a signed-in account.

Locations, data categories, and safeguards are visible to signed-in customers.

Sign in
SubprocessorPurposeLocationData categoriesAgreementSafeguards
Amazon Web ServicesCloud infrastructure & data hostingSign in to viewSign in to viewSign in to viewSign in to view
VercelWeb application hosting & CDNSign in to viewSign in to viewSign in to viewSign in to view
NeonManaged PostgreSQL databaseSign in to viewSign in to viewSign in to viewSign in to view
RailwayApplication backend & background job hostingSign in to viewSign in to viewSign in to viewSign in to view
StripePayment processing, transaction settlement, merchant fraud prevention, financial reportingSign in to viewSign in to viewSign in to viewSign in to view
ResendTransactional email deliverySign in to viewSign in to viewSign in to viewSign in to view
TwilioSMS & voice notificationsSign in to viewSign in to viewSign in to viewSign in to view
PostHogProduct analyticsSign in to viewSign in to viewSign in to viewSign in to view
OpenAIAI language model inference for product featuresSign in to viewSign in to viewSign in to viewSign in to view
ElevenLabsText-to-speech voice synthesisSign in to viewSign in to viewSign in to viewSign in to view
LiveKitReal-time voice & audio infrastructure (WebRTC)Sign in to viewSign in to viewSign in to viewSign in to view
DeepgramSpeech-to-text transcriptionSign in to viewSign in to viewSign in to viewSign in to view

Documents

Compliance documentation available to customers and prospects.

Data Processing Agreement (DPA)
Sign in required
Our standard DPA incorporating Standard Contractual Clauses. Generate a signed copy for your business from this portal.
Business Associate Agreement (BAA)
Sign in required
HIPAA BAA for covered entities and business associates.
Need a Data Processing Agreement?
Signed-in customers can generate a DPA pre-signed by Filohealth Software, Inc., made out to their own business name, in under a minute.