Your clients trust you with the worst moments of their lives. We build Bespoke OS so that trust is structural — enforced in how the system works, not just promised in a policy. Here’s what’s built in today, and the formal assurances we’re pursuing ahead of our Q3 2026 launch.
Every database query is scoped to your firm's ID at the API layer — no shared views, no cross-firm reads. Isolation is enforced by automated tests that run against every resource type.
Your provider keys (email, phone, storage, AI) are encrypted at rest with Fernet symmetric encryption. Secrets are decrypted only in memory at the moment of use and never written to logs.
Inbound events are cryptographically verified before they touch your data: HMAC-SHA256 for voice-AI transcripts and email sync, Ed25519 for carrier SMS. Unsigned traffic is rejected.
Your firm brings its own carrier, email and voice accounts. Keys are yours, numbers are yours, data is yours — Bespoke orchestrates, it doesn't own.
Calls to large language models are processed and discarded. Your case files, medical records and client communications are never used to train models.
Documents live in dedicated cloud object storage behind a signed-URL layer, with per-firm path scoping and no public buckets.
Staff and client-portal sessions use separate JWT token types with distinct scopes — a portal token can never touch staff endpoints.
AI-extracted facts (medical visits, triage classifications) land as pending until a human confirms them. Nothing AI-generated becomes case-of-record silently.
We’re building toward formal, third-party-verified security assurances ahead of general availability. If your firm or your clients require specific attestations, tell us — it shapes our priorities.
Working toward SOC 2 examination with continuous compliance monitoring, so our controls are independently verified — not just self-described.
Independent security testing planned before general availability, with findings remediated and summarized for customers.
We'll complete your firm's or your clients' security due-diligence questionnaires as part of early access.
Medical records flow through the platform, so we're evaluating the safeguards and agreements that class of data demands.
Statuses above describe work in progress and planned initiatives, not completed certifications.
We'll walk your team through the architecture directly.