Security & Trust

CallRoom handles clinical workflow content, so the infrastructure underneath it doesn't get to be an afterthought. Here is what that actually means.

Encrypted, always

Every connection uses TLS in transit. Clinical content is encrypted at rest with AES-256-GCM. Encryption keys never touch a client device.

Every access, logged

A two-layer audit system records who touched what, when, and why, retained for six years in line with HIPAA documentation requirements. No one reviews clinical content without leaving a trace.

Minimum necessary, by design

CallRoom only collects what a clinical workflow actually needs, and never asks for more identifying detail than a task requires.

AI runs server-side

Clinical input never goes straight from your device to a third-party AI API. It passes through access-controlled infrastructure we operate, under our Business Associate Agreement, every time.

Business Associate Agreement

Jinka Technologies has an executed Business Associate Agreement with our cloud infrastructure provider, covering every service that touches clinical content.

Patent-pending technology

The core technology is patent-pending. CallRoom was built as clinical infrastructure from day one, not a chat window bolted onto someone else's AI model.

How CallRoom is built differently

Most new clinical AI products send your input straight to a general-purpose AI API, with no audit trail behind it. CallRoom runs every AI call through infrastructure we control, logs every touch of clinical content, and only collects what it needs to. It took longer to build it this way. We think it's the right way to build software that touches patient care.

Deploying at a program or institution?

We'll execute a Business Associate Agreement directly with your institution before any deployment.

Contact legal@callroom.md