SECURITY
Security overview
A plain-language overview of the controls currently built into the Vetnivo pilot.
Access controls
The application requires authenticated sign-in. Pilot access is restricted to explicitly invited email addresses. Administrative routes use a separate owner check, and revoked practice accounts lose API and application access.
Practice separation
Consults, catalogs and usage records are scoped to a practice identifier on the server. Prices, tax rates and codes come from that practice’s active catalog—not from the AI model.
Data handling
Traffic uses HTTPS. The application does not retain raw consult audio. Transcripts and reviewed documents are stored in the practice environment, and account owners have an in-product deletion control.
AI safeguards
Generated notes remain drafts until reviewed. Procedure suggestions can only reference active catalog entries, include source evidence and use a catalog-match score rather than a medical-confidence claim.
Responsible reporting
If you believe you found a security issue, do not access other users’ data. Send a concise report to info@vetnivo.com so it can be investigated.
Before real patient use
Each practice remains responsible for its own risk assessment, processing agreement, staff instructions and lawful use. A formal security and privacy review is still required before commercial launch.