Security & trust

Patient data is the reason clinics distrust marketing software.

So here is exactly what we do with it, what we will never do with it, and what we are not yet entitled to claim. If your procurement team needs something not on this page, email security@shmel.ai and we will answer it directly.

What Shmel does, and what it will never do

What it does
  • Reads last-visit dates and treatment history to know who is due back
  • Drafts messages and campaigns for a named human to approve
  • Writes approved appointments back to your calendar
  • Sends aggregate performance figures to your ad accounts
What it will never do
  • Upload a patient record, list or identifier to Meta or Google
  • Build custom or lookalike audiences from your patients
  • Send anything to a patient without a human approving it
  • Make, suggest or influence a clinical decision
  • Order a prescription product on its own

Where we actually stand

Vendors overstate this constantly. We would rather lose a deal than claim a certification we do not hold.

CLAIM · STATUS
Business Associate AgreementAvailable and signed before any data moves
Encryption in transit and at restIn place
Role-based access, staff access loggedIn place
SOC 2 Type IIIn progress. Not yet held, and we do not claim it
Penetration test reportScheduled, not yet completed
HIPAA "certification"Does not exist. No body certifies it. Be wary of anyone claiming it

There is no such thing as HIPAA certification. What exists is a Business Associate Agreement and the controls behind it, which is what we offer and what you should ask every vendor for.

Sub-processors

Every third party that could touch your data, what it sees, and whether it is covered by a BAA. We give notice before adding one that can handle protected health information.

VENDOR · PURPOSE · BAA
Cloud hostingApplication and database · BAA in place
Model inferenceDrafting and analysis · contractual no-training terms
Transactional email and SMSApproved patient messaging · BAA in place
Error monitoringDiagnostics · scrubbed of patient data
Payment processingBilling you, never your patients · no PHI

Named vendors are provided on request under NDA, and always before you sign. Email security@shmel.ai.

Questions procurement always asks

Do you train models on our data?

No. Nothing from your practice is used to train general-purpose models, and our contracts with model providers carry no-training terms. This is the single most common vendor lie in this category, so ask every one of them for it in writing.

Where is data hosted?

United States. If you have a residency requirement beyond that, tell us before you sign rather than after.

How long do you keep our data?

Patient data for the life of the account plus thirty days, then deleted. Compliance records for six years, because their entire value is that they can be produced later. You can export everything at any time and request earlier deletion.

What happens if you are breached?

Under the BAA we notify you without unreasonable delay so you can meet your own HIPAA breach-notification obligations. We would rather tell you early and be wrong than late and be right.

How do we report a vulnerability?

Email security@shmel.ai. We acknowledge within one business day. We will not pursue anyone acting in good faith.

Can we get a security questionnaire completed?

Yes. Send it over. A founder will fill it in — we are small enough that it will not sit in a queue.