Your data is protected.

By design.

Built entirely on Microsoft Azure’s HIPAA-eligible infrastructure. Every layer engineered for healthcare-grade security and regulatory compliance.

HIPAA · BAA in Place
BAA Signed
AES-256 Encryption
U.S. Data Residency
Microsoft Azure
Non-Profit Parent
AHI SOC 2 Type 2 and HITRUST CSF certification in progress.
Built on Microsoft Azure

Built entirely on Microsoft Azure's HIPAA-eligible infrastructure, under a signed Business Associate Agreement with Microsoft. Azure holds HITRUST CSF, FedRAMP High, ISO 27001, ISO 27018, and SOC 2 authorizations covering the infrastructure layer. Those are Azure's certifications, not ours — AHI's own SOC 2 Type 2 and HITRUST CSF are in progress.

Who Touches Your Data

Microsoft Azure is our infrastructure. Compute, storage, database, networking, key management, and real-time messaging all run on Azure under a signed Business Associate Agreement with Microsoft — this is where your data lives and where our APIs run. AI inference runs on OpenAI and Anthropic models, reached either through Azure's own AI endpoints or directly, depending on the workload; every path is covered by a signed Business Associate Agreement with zero data retention. Auth0 handles sign-in and Stripe handles billing; neither receives clinical content. That is the complete list — we publish every one of them, what they receive, and why. See the full subprocessor list →

Mission-aligned, not investor-driven. HALai, Inc. operates the platform as a wholly-owned subsidiary of Artificial Healthcare Intelligence, Inc., a 501(c)(3) non-profit. We do not sell your data, and we do not monetize patient information.

Dr. Zishan Merza

Chief Security Officer
PhD in Cybersecurity · 30+ years in security architecture, threat analysis, and enterprise infrastructure protection.

Dr. Merza leads security strategy and oversees every layer of AHI's infrastructure, from tenant isolation to AI processing controls. His work spans three decades of cybersecurity practice across enterprise systems, healthcare data environments, and government-grade threat analysis. At AHI, he owns the architecture that protects every encounter note flowing through the platform.

security@halai.ai

Six layers of protection, wrapped around every encounter note.

Your patients' data. Protected the way it should be.

Can other providers see my patients' data?

No. Your data lives in its own dedicated container and database partition, isolated at the data layer. No other provider, practice, or organization can access your patients' information.

Is this HIPAA compliant?

HIPAA has no certification program, so no vendor can truthfully call itself "HIPAA certified." What we can tell you is specific: we act as your Business Associate under a signed BAA, we run on Microsoft Azure's HIPAA-eligible infrastructure under a BAA with Microsoft, and every subprocessor that touches PHI is itself under a BAA with us.

Will my data be used to train someone else's product?

Never. In fact, your encounter notes are not used to train any AI model at all — not ours, not a vendor's, and not one that serves another customer. We do not train models. Inference runs on OpenAI and Anthropic models — reached through Azure's AI endpoints or directly, depending on the workload — and in every case under a signed BAA with zero data retention, meaning your content is processed to answer your request and not retained afterward. Your own notes shape your own results because they are retrieved at the moment you ask, not because a model was trained on them. No model weights anywhere hold your PHI.

What happens if I want to leave?

You own your data. For 90 days after termination we make it available for export in standard formats, and after that we return or destroy it at your direction under the Business Associate Agreement. The only exception is where law requires us to retain something longer, in which case we isolate it and delete it when that obligation ends.

Do I need my IT department to set this up?

No. There is nothing to install, no EHR integration required, no IT cooperation needed. You upload your encounter notes directly. Your IT department and your EHR vendor do not need to be involved.

Where is my data stored, and who else touches it?

United States only — Microsoft Azure data centers on U.S. soil, with no offshore processing and no offshore support access. Azure runs our infrastructure and, for some workloads, the AI models themselves. Where inference goes directly to OpenAI or Anthropic instead, those calls are covered by our own BAAs with each of them, with zero data retention. Auth0 handles sign-in and Stripe handles billing; neither receives clinical content. We publish the full list. See subprocessors →

What happens to documents I upload?

Text extraction happens on your own device. When you upload a PDF, scan, or Word document, the OCR and parsing run inside your browser — the source file is not sent to a server to be read. Only the extracted text moves into your isolated container. This keeps the raw document, and everything incidental in it, off our infrastructure entirely.

Your data works for you. And nobody else.

  • Your encounter notes are never used to train any AI model.
  • Your data is never shared with other providers or organizations.
  • We do not train models. Your notes ground your results, not a model's weights.
  • AI inference runs under signed BAAs with zero data retention.
  • Voice audio is processed during your session and not stored afterward, unless you save it to a note.
  • You can request deletion of your data at any time.

We don't monetize your patient data. HALai, Inc. is a wholly-owned subsidiary of Artificial Healthcare Intelligence, Inc., a 501(c)(3) non-profit. Every third party that touches your data is named on our subprocessor list.

Every layer, documented and auditable.

HIPAA · BAA in Place

We act as your Business Associate under a signed BAA, executed at signup. Microsoft Azure is under a BAA with us, and so is every subprocessor that handles PHI. HIPAA-eligible infrastructure from day one.

Infrastructure Certifications

Our infrastructure provider, Microsoft Azure, holds HITRUST CSF, SOC 1/2/3, ISO/IEC 27001/27017/27018, and FedRAMP. Those are Azure's certifications. AHI's own SOC 2 Type 2 and HITRUST CSF are in progress.

Encrypted. Isolated. Yours.

AES-256 at rest, TLS 1.2 or higher in transit. Each provider's data in its own dedicated Azure container and partition. Private Link network isolation between our services.

Document Parsing Stays Local

OCR and document text extraction run in your browser, not on our servers. The source file never leaves your device — only the text you're working with does.

BAA at Signup

Executed as part of the Healthcare Provider User Agreement when you create your account — the standard clickwrap approach in healthcare software. A standalone countersigned BAA is available on request.

You Own Your Data

Export in standard formats for 90 days after termination, then return or destruction at your direction. U.S. data residency. Every subprocessor named publicly — see the list.

Start your security review.

Request access to AHI's security documentation package, including our BAA, data architecture overview, subprocessor list, and pre-answered security questionnaire responses.

Request Security Package
Available on request Security overview · BAA template · Data flow diagram · Subprocessor list · Security questionnaire response · Incident response summary · BC/DR overview

Healthcare-grade security. Not an afterthought.