Security & HIPAA Compliance
Your clients trust you with their health and beauty. Every signature, every amendment, every access — permanently recorded and encrypted.
Encryption everywhere
- AES-256 field-level encryption on-device (Apple CryptoKit, hardware-backed keys) and in the cloud.
- TLS 1.2+ for every connection; outbound email is TLS-required — never delivered in the clear.
- Zero third-party SDKs in the app — no analytics, no trackers, no third-party code.
HIPAA compliant
- Full compliance program: risk assessments, role-based access, 6-year tamper-proof audit retention on write-once storage.
- Business Associate Agreement (BAA) on Elite and Empire — reviewed and signed electronically in the app, recorded immutably, downloadable anytime.
Tamper-evident documents
- Every submission is cryptographically sealed at creation; the app shows a verified-integrity badge.
- Public verification at getconsentify.com/verify — any recipient can confirm a document is authentic, no account needed.
- Immutable audit trail: who, what, when, and why for every change — amendments are append-only.
Device security
- PIN lock with Face ID / Touch ID, auto-lock, and progressive lockout.
- Remote device blocking with local data wipe; per-plan device limits; geo-IP registration tracking.