Security
Last updated August 13, 2026
Ünfold provides software to licensed clinicians and handles sensitive information about their Clients. Security is a foundational requirement of how we operate.
This page describes Ünfold's current security posture. It is updated as practices change.
Security contact
For vulnerability reports, security concerns, BAA requests, and security questionnaires, contact us through your Ünfold account. We aim to respond within one business day.
Compliance posture
HIPAA
Session recordings, transcripts, and notes may include PHI. Ünfold is designed for clinical workflow and applies administrative and technical safeguards intended to protect that data. Do not submit PHI until a Business Associate Agreement is in place. A BAA, when executed, governs PHI and takes precedence over conflicting terms.
SOC 2
Ünfold is not SOC 2 certified at this time. No claim of certification will be made prior to issuance of an audit report.
Infrastructure
- Application hosting and data stores. The application runs on modern cloud infrastructure. Session audio and structured data are stored with Supabase.
- Encryption in transit. TLS on public endpoints.
- Tenancy. Multi-tenant application with logical isolation per Customer account.
- Audio retention. Session audio is deleted from storage as soon as transcription and notes finish. Unprocessed leftover audio is removed after 7 days. Transcripts, notes, and briefs are kept so you can continue clinical workflow after audio is gone.
Authentication and access
- Sign-in. Passwordless login via one-time passcode delivered to a verified email address. Reusable passwords are not stored by Ünfold.
- Account isolation. Customer Data is scoped to the signed-in therapist account.
- Least privilege internally. Access to production systems is limited to what is required to operate and support the Services.
AI and subprocessors
Ünfold uses third-party services for authentication, hosting, transcription, AI drafts, and email. We do not use Customer Data to train our own AI models. Names and personal relationships are replaced with placeholders before draft generation. Audio is sent for transcription in short clips, then deleted from storage. Current subprocessors include:
- Clerk — authentication;
- Supabase — database and file storage;
- Deepgram — speech-to-text;
- OpenAI — draft notes, briefs, and related AI features;
- Resend — transactional email, including Client summaries you choose to send.
Application security
- Production changes are reviewed before they ship;
- Secrets are kept out of source control;
- Signed, time-limited URLs are used when audio must be retrieved for playback or processing.
Responsible disclosure
If you identify a vulnerability in Ünfold, please report it through your account contact channel. Include a description of the issue, the affected asset, steps to reproduce, and any supporting evidence.
Do not access, modify, retain, or disclose PHI or personal data belonging to other users. If you encounter PHI while testing, stop immediately and report. Do not perform testing that disrupts service to other users, and do not exfiltrate data — a proof of concept is sufficient.
Incident response
Security incidents are investigated promptly. Where an incident affects Customer Data, we will notify affected Customers as required by any BAA and applicable law.
Current gaps
We disclose the following gaps in the current program:
- SOC 2 report: not yet available;
- Independent penetration test: planned; not yet published;
- Public paid bug bounty: not currently offered.
This section is updated as status changes.
Privacy
Collection, use, and disclosure of personal information are described in the Privacy policy. The Terms of service govern use of the Services. To the extent of any conflict regarding PHI, a BAA controls.
