For clinical teams

HIPAA-compliant collaboration for healthcare teams

Secure messaging, telehealth video and the clinic queue in one platform — encrypted, audited, and built around the way care teams actually work.

Start free

One workspace for the whole care team

Clinical work does not divide neatly into a chat app, a video app and a task tracker, so it stops being three products here. Conversations, meetings, task boards and the patient queue live in one workspace, and a Space keeps a team's work to that team — its board is visible to its members and to nobody else in the organisation.

  • Channels and direct messages, with mentions, files and threaded replies
  • Video meetings started from any conversation, or scheduled ahead
  • Task boards per Space, with the stages your clinic actually uses
  • A shared whiteboard beside the cards that track the work

Built for PHI, not adapted for it

Handling patient data was the starting requirement, not a compliance module added later. Content tables carry soft-delete and retention columns so a record can be removed and stay removed; the audit log is append-only, so what happened cannot be quietly rewritten; and AI features are gated per organisation rather than switched on for everyone by default.

  • Append-only audit log covering access, changes and administrative actions
  • Soft-delete plus retention windows on the tables that hold content
  • Per-organisation control over whether AI ever sees clinical data
  • Every request re-checks the caller's organisation and membership

Your data stays on your infrastructure

There is no third-party processor sitting in the middle of this. The database, the video server, file storage and even speech-to-text run on infrastructure we operate — which means audio for live captions is transcribed without leaving the server, rather than being posted to somebody else's transcription API and becoming their copy of your consultation.

  • Self-hosted PostgreSQL, not a managed database on a shared platform
  • Self-hosted video server, so media is not routed through a third party
  • Speech-to-text on our own hardware — caption audio never leaves it
  • Private file storage with time-limited links, never public objects

Healthcare mode, when a conversation cannot be recorded

Some consultations should leave nothing behind at all. Healthcare mode is end-to-end encrypted — the encryption key is generated in the browser and never reaches our servers — and it persists nothing: no recording, no transcript, no summary. Recording and broadcasting are not discouraged in that mode, they are refused outright by the server.

  • Keys generated in the browser; the API never receives one
  • Recording, broadcasting and captions all refused, not merely hidden
  • Nothing written to disk: no transcript, no summary, no recording
  • Cannot be switched on mid-meeting, so the guarantee covers the whole call

Common questions

Is WorkStation HIPAA compliant?
The platform is built to HIPAA requirements: encrypted transport, an append-only audit log, retention and deletion controls, per-organisation access boundaries, and infrastructure we operate ourselves. Compliance is a shared responsibility, so talk to us about your specific workflow and a business associate agreement before handling PHI.
Will you sign a business associate agreement?
A BAA is part of our enterprise terms. Contact us with your requirements and we will work through the agreement alongside the technical review your organisation needs.
Where is our data stored?
On infrastructure we operate directly — our own database, our own video servers, our own storage. Nothing is handed to a managed third-party platform, and we can tell you exactly where every category of data lives.
Can we stop meetings being recorded?
Yes. Healthcare mode refuses recording entirely, at the server rather than by hiding a button. In every other mode, recording is announced to everyone in the room the moment it starts — a visible badge and a banner, driven by the meeting server rather than by the recorder's own client.
Does the AI assistant see patient data?
Only if your organisation explicitly enables it. AI is gated per organisation by a single setting, and every AI run is written to the audit log with the model and the outcome — never the prompt and never the output.

See it with your own workflow

Start free, or talk to us about a clinical rollout and the agreements your organisation needs.

Get started