Skip to main content
Access is decided by three things together: the role of the person asking, the purpose of the request, and the Consent attached to the record. Any one of them failing denies the request.

Core principles

  • Collect only what a workflow needs.
  • Store identity data apart from clinical data.
  • Scope every sensitive access, and write it to an audit trail.
  • Let People decide what is shared, and with whom.
  • Keep private Care content out of product analytics entirely.

In transit

Every response is served over HTTPS with HSTS. Browsers are told to refuse framing, ignore MIME sniffing, send a lean referrer and keep device permissions limited to what a Session needs.

Clinical boundaries

Iris may draft Clinical Notes, but a Practitioner must review and approve them before they become part of the approved record.

Organization access

Organizations receive aggregate reporting for the Programs they fund. Those reports never include a Person’s identity, diagnosis, Session content or private Conversation.

What Iris learns from

Iris improves from whether a suggestion was accepted, edited or dismissed. She does not learn from Session content, Messages, Journals or Check answers, and those are never used to train product models, regardless of any setting.

Reporting a vulnerability

Send security concerns to hello@heyrafiki.space. Do not include passwords, keys or clinical records in a first message. We acknowledge reports and agree a fix and disclosure timeline with the reporter.
Last modified on July 25, 2026