Where patient data lives
Patient data is processed by five vendors and no others: Anthropic for AI, Twilio for SMS and WhatsApp, Meta for Instagram and Facebook Messenger, Neon for the database, Render for the application.
// Data and security
Every statement on this page describes how the system is built today, not how we intend to build it. Architecture is checkable in a way that a policy promise is not.
Patient data is processed by five vendors and no others: Anthropic for AI, Twilio for SMS and WhatsApp, Meta for Instagram and Facebook Messenger, Neon for the database, Render for the application.
Ascend is established in Pakistan, and the people who run and support the service access it from there. That is an international transfer of data, and it belongs on this page rather than in a footnote you find during diligence. The access is bound by every control below, and we will agree specific transfer safeguards or residency commitments in your agreement if you need them.
Authentication, hosting for the marketing site, background jobs, caching and error monitoring are all architected so patient data never reaches them. That is a design constraint, not a policy promise.
Every practice's data is isolated at the database level by row level security, which is enforced by the database rather than by application code remembering to filter. Clinical records are additionally role gated.
Opening a patient's clinical record writes an audit row inside the same transaction as the read. If the log write fails, the read fails. There is no path that reads a chart without recording it.
Clinical context reaches AI through an audited accessor in code, never by giving a model access and instructing it not to look. Clinical AI runs on Anthropic only.
Export any time. Thirty days notice. No exit fee. Ask us to stop contributing to the Network and we stop. Your past contributions stop counting as current evidence and decay out of it, and no identifier of your practice was ever stored in it to begin with.
Publishing this table is unusual, and it is the point. A careful buyer can check every name on it, and the ones marked no are architected so patient data cannot reach them.
| Subprocessor | Purpose | Patient data |
|---|---|---|
| Anthropic | AI reasoning and drafting | Yes |
| Twilio | SMS and WhatsApp messaging | Yes |
| Neon | Application database | Yes |
| Render | Application hosting | Yes |
| Meta Platforms | Instagram Direct and Facebook Messenger message transport | Yes |
| Clerk | Staff authentication | No |
| Resend | Delivers enquiries sent through this website | No |
| Vercel | Marketing site and dashboard hosting | No |
| Inngest | Background jobs | No |
| Sentry | Error monitoring | No |
Patient data is processed by 5 vendors and no others: Anthropic, Twilio, Neon, Render, Meta Platforms. Everything else on this list is deliberately blind to it.
Ascend acts as a business associate to your practice. HIPAA compliance is a shared responsibility and we will walk through the agreement on the call. We do not print a certification badge, because no such certification exists.
The full detail of what we collect and why is in the privacy policy, and deletion instructions are here.
Not the worked example from earlier. Yours. You will see the actual figure for your practice, with every assumption named and arguable.
If the number is not big enough to justify the fee, that is a completely reasonable outcome and we will tell you on the call rather than chase you for a quarter.