SECURITY & TRUST
Green — Administrative
Amber — Protocol-bound care
Red — Never
Every SkinTwin interaction falls into one of three zones. The boundaries are enforced by the system, not left to a script. Administrative: booking, rescheduling, hours, directions, pricing and policy answers from your approved knowledge base. Protocol-bound care: clinician-approved instructions and follow-ups, delivered word for word. Never: diagnosis, symptom assessment, or medical advice — the AI flags the conversation and escalates to your clinical team immediately.
AI Disclosure Engine — every conversation opens by identifying the assistant as AI, and any patient who asks gets an immediate, honest answer. Disclosure is enforced by the platform on every channel — so you’re never one edited script away from a compliance gap.
Data security
Encryption in transit and at rest. Strict tenant isolation, so one clinic’s data is never mixed with another’s. PHI redaction, role-based access control, and complete audit logs on every interaction — so you can always see who accessed what, and what the AI said.
Auditability by default
Disclosure, escalation, and audit logging are enforced by the platform, not left to a script or a manual process.
Biometric consent & deletion
Voice recognition is strictly opt-in and captured with recorded consent. Voiceprints are encrypted, used only to recognize returning patients, and can be deleted per patient at any time. Biometric processing follows state law, including BIPA and CPRA.
Certifications & BAAs
SkinTwin signs a HIPAA Business Associate Agreement with every clinic, and maintains BAAs with all subprocessors. Our architecture is HIPAA-ready, and SOC 2 Type I is in progress.