Trust center
Yobi Trust Center
Demonstrating our commitment to patient privacy for AI-powered healthcare solutions. View our technical safeguards, security controls, and compliance framework that protect sensitive health information while enabling intelligent customer interactions.
- BAA available on request
- Encrypted at rest (AES-256)
- US-based production servers
Controls
Security Controls
Technical security controls and organizational safeguards currently implemented.
Infrastructure Security
7 controls
The company requires authentication to production datastores to use authorized secure authentication mechanisms, such as unique SSH key.
The company requires authentication to systems and applications to use unique username and password or authorized Secure Socket Shell (SSH) keys.
System access restricted to authorized access only
The company restricts privileged access to databases to authorized users with a business need.
The company's production systems can only be remotely accessed by authorized employees possessing a valid multi-factor authentication (MFA) method.
The company's production systems can only be remotely accessed by authorized employees via an approved encrypted connection.
The company uses firewalls and configures them to prevent unauthorized access.
Organizational Security
4 controls
The company maintains a formal inventory of production system assets.
The company deploys anti-malware technology to environments commonly susceptible to malicious attacks and configures this to be updated routinely, logged, and installed on all relevant systems.
The company requires passwords for in-scope system components to be configured according to the company's policy.
The company has a mobile device management (MDM) system in place to centrally manage mobile devices supporting the service.
Product Security
2 controls
The company's datastores housing sensitive customer data are encrypted at rest.
The company performs control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Corrective actions are taken based on relevant findings. If the company has committed to an SLA for a finding, the corrective action is completed within that SLA.
FAQ
Frequently Asked Questions
Common questions about our security and patient privacy protections.
Want to report a potential security issue?
Please email us at [email protected]. We take all security reports seriously and respond within 24 hours.
Do you encrypt data at rest?
All of our production data is encrypted at rest using AES-256 encryption on secure instances. Data in transit is also encrypted, though some channels like SMS may not support end-to-end encryption.
Where are your servers located?
All of our production servers are located in the United States in SOC 2 compliant data centers with 24/7 physical security monitoring.
Does Yobi sign Business Associate Agreements (BAAs)?
Yes, we sign BAAs with healthcare organizations. The specific terms depend on your use case and requirements. To initiate this process, please email us directly at [email protected].
What certifications do you have?
Yobi is built for patient privacy, with a BAA available on request, and we are actively working towards SOC 2 Type II certification. We also maintain ongoing security assessments and penetration testing.
Contact Information
Report a potential security issue: [email protected]
Business Associate Agreements: [email protected]