Skip to content

// Data and security

Where your patients' data lives, and who can reach it.

Every statement on this page describes how the system is built today, not how we intend to build it. Architecture is checkable in a way that a policy promise is not.

01

Where patient data lives

Patient data is processed by five vendors and no others: Anthropic for AI, Twilio for SMS and WhatsApp, Meta for Instagram and Facebook Messenger, Neon for the database, Render for the application.

02

Where Ascend itself sits

Ascend is established in Pakistan, and the people who run and support the service access it from there. That is an international transfer of data, and it belongs on this page rather than in a footnote you find during diligence. The access is bound by every control below, and we will agree specific transfer safeguards or residency commitments in your agreement if you need them.

03

Who is deliberately blind

Authentication, hosting for the marketing site, background jobs, caching and error monitoring are all architected so patient data never reaches them. That is a design constraint, not a policy promise.

04

How access is controlled

Every practice's data is isolated at the database level by row level security, which is enforced by the database rather than by application code remembering to filter. Clinical records are additionally role gated.

05

Every clinical read is logged

Opening a patient's clinical record writes an audit row inside the same transaction as the read. If the log write fails, the read fails. There is no path that reads a chart without recording it.

06

AI and your clinical data

Clinical context reaches AI through an audited accessor in code, never by giving a model access and instructing it not to look. Clinical AI runs on Anthropic only.

07

Your data is yours

Export any time. Thirty days notice. No exit fee. Ask us to stop contributing to the Network and we stop. Your past contributions stop counting as current evidence and decay out of it, and no identifier of your practice was ever stored in it to begin with.

// Subprocessors

5 vendors may touch patient data. That is the whole list.

Publishing this table is unusual, and it is the point. A careful buyer can check every name on it, and the ones marked no are architected so patient data cannot reach them.

SubprocessorPurposePatient data
AnthropicAI reasoning and draftingYes
TwilioSMS and WhatsApp messagingYes
NeonApplication databaseYes
RenderApplication hostingYes
Meta PlatformsInstagram Direct and Facebook Messenger message transportYes
ClerkStaff authenticationNo
ResendDelivers enquiries sent through this websiteNo
VercelMarketing site and dashboard hostingNo
InngestBackground jobsNo
SentryError monitoringNo

Patient data is processed by 5 vendors and no others: Anthropic, Twilio, Neon, Render, Meta Platforms. Everything else on this list is deliberately blind to it.

Ascend acts as a business associate to your practice. HIPAA compliance is a shared responsibility and we will walk through the agreement on the call. We do not print a certification badge, because no such certification exists.

The full detail of what we collect and why is in the privacy policy, and deletion instructions are here.

// The ask

Send us your last twelve months. We will run your own numbers through the four leaks.

Not the worked example from earlier. Yours. You will see the actual figure for your practice, with every assumption named and arguable.

If the number is not big enough to justify the fee, that is a completely reasonable outcome and we will tell you on the call rather than chase you for a quarter.