Compliance and documentsIn writing, before you sign.
The agreement that governs your patients’ data, the deadlines we hold ourselves to, how each state’s rules are handled, and every document your IT consultant will ask for.
One agreement, signed first.
Your practice is the covered entity; we are its business associate. The Business Associate Agreement puts our obligations in writing before any patient data exists.
Signed before any data
No call for your practice is answered and no practice data is touched before your BAA is signed. It comes before the phone line, the PMS connection and the test calls.
One BAA covers every license
A single standard agreement, e-signed, with your choices in an order form. No per-practice variants, and no new agreement when you change license.
Our suppliers, under theirs
Everything that holds your practice’s data runs on AWS under our Business Associate Addendum with AWS, in a United States region.
Our standard BAA is being finalized with counsel. It is signed before any call is answered.Request the BAA
A first notice within 10 calendar days.
Our BAA commits us to tell your practice within 10 calendar days of discovering a breach that affects it. If Florida law sets an earlier date, the earlier date governs.
- Day 0
Discovery
We find, or are told of, a breach that affects your practice.
- By day 10
First notice to you
What happened, what data, what we have done. In writing.
- After
Details as we learn them
Each update as the facts are confirmed, until the review is closed.
Recording consent and AI disclosure, state by state.
Recording and AI-disclosure rules differ by state. We switch a state on only after counsel has cleared it, and we will not claim anything we have not checked for yours.
Disclosure on every call
Leady is built to open every call by telling the caller they are speaking to an automated assistant and that the call is transcribed.
Audio waits for counsel
Call audio is off in every state until counsel clears that state's consent rules. No state is cleared today.
States open one at a time
Patient calls start in a state only after our legal review clears it and counsel gives the go-ahead. Florida is first.
| State | AI disclosure | Opening line | Call audio |
|---|---|---|---|
| Florida | Every call | Wording being set with counsel | Off · under legal review |
| Every other state | Every call | Set with counsel as each state opens | Off until cleared |
Opening line, every call"You are speaking with Palmetto Bay Family Dental's automated assistant. This call is transcribed."
Illustrative wording. The final line is set with counsel. Sample practice.
Not SOC 2 certified.
We plan the audit after our first practices go live. No audit date is published until an auditor is engaged.
Not claimed- First
Our controls, written down
Each control an auditor would test, with the evidence that shows it works. The ones in place are listed on this page.
- Next
First practices go live
Onboarding one practice at a time, so controls run on a real system and leave a record.
- Then
The audit
Planned after our first practices go live. No date is published until an auditor is engaged.
What is in place, with the evidence behind it.
Each control below runs today, and each points at a test, a configuration or a recorded read that we can show your reviewer. The ones not yet in place are counted, not described.
Data and privacy
- Leady staff cannot play call audioIn placeThe database refuses any audio play by a Leady administrator, so only the practice's own authorised staff can listen to a call.
- No patient data in application logsIn placeCode that handles patient data may not pass it to the application log, and an automated check fails any change that does.
- No patient data in web addressesIn placePortal addresses use opaque identifiers, so patient details never appear in browser history or request logs.
Infrastructure security
- Database encrypted at restIn placeThe application database is encrypted at rest and protected against accidental deletion.
- Verified encryption in transit to the databaseIn placeThe application refuses to connect to a remote database unless the connection is encrypted and the server's certificate is verified.
- Data hosted in the United StatesIn placeThe application database runs in a United States region.
- Account activity trailIn placeEvery change to our cloud account is recorded in a tamper-evident trail across all regions.
- Strong password policy on the cloud accountIn placeCloud account passwords must be at least 14 characters, mixed, and never reused.
Product security
- Practice data isolationIn placeEvery portal request is scoped to the signed-in practice, so one practice can never read another's data.
- Invite-only portal accountsIn placeNobody can create a portal account without an invitation from the practice or from Leady.
- No internal error details in responsesIn placeError responses never return an internal error message, stack trace or raw validation detail to the caller.
- Double booking refused by the databaseIn placeThe database itself refuses two bookings for the same chair at the same time.
Organizational security
- Work laptop disk encryptionIn placeThe work laptop's disk is encrypted.
- Work laptop firewallIn placeThe work laptop's firewall is on and file sharing is off.
Internal security procedures
- Automated checks on every changeIn placeEvery code change is checked automatically with a typecheck, the full test suite, a build and a secret scan.
- Booking rules tested against a real databaseIn placeEvery code change runs the booking and data-access tests against a real database, not a mock.
Subprocessors by role
- Staff sign-inIn placeThe staff sign-in service holds staff identities and roles only, never patient data.
The full list, with what is missing from each control that is not yet in place, is in the security overview.
Who else touches practice data.
Every supplier we use, what it does for us, what it sees and the agreement we hold with it.
| Supplier | What it does for us | What it sees | Agreement |
|---|---|---|---|
| AWS | Hosting, the voice line, the speech model, the database and storage | Patient dataPractice and patient data | Business Associate Addendum in place |
| Clerk | Staff sign-in to the portal | No patient dataStaff names, work emails and roles | Standard terms |
| Stripe | Billing the practice | No patient dataThe practice's billing details | Standard terms |
| HubSpot | Our sales records | No patient dataProspects who contact us | Standard terms |
| Google Workspace | Company email, calendar and documents | No patient dataNo patient data by design | Business Associate Agreement in place |
A supplier that would handle patient data is added here only after it has signed a Business Associate Agreement with us.
Open Dental is your system, not our supplier: Leady connects to it with your permission, through your own connector.
If this list changes, this page changes with it.
Everything your reviewer will ask for.
We share the BAA before you sign anything, and the rest on request. Write to security@meetleady.com, or use the form on the overview page.
- Before you sign
Business Associate Agreement
Our standard BAA, the same for every license.
Request - On request
Privacy notice
What we collect, why, and for how long.
Request - Online
Terms of service
The customer agreement, readable online.
Read - On request
Security overview
How we protect practice data, for your IT consultant.
Request - On request
Subprocessor list
Each supplier by name, what it sees, and its agreement.
Request
If something goes wrong.
Four steps, written down before we need them. We have never had a security incident, because no practice runs on Leady in production yet.
Being builtRunbook written; put into force before the first practice- 01
Detect
A supplier notice, a staff report or a message to security@. Every suspected event goes in an incident log, even when it turns out to be nothing. Automatic alerts are being built.
- 02
Contain Coming
Stop the exposure first: revoke keys, close access, pause what is affected. An emergency off switch for call handling is being built.
- 03
Notify Coming
Your practice hears from us within 10 calendar days of discovery, then again as details are confirmed. Written notice templates are being prepared.
- 04
Review
What happened, why, and what changes. The review is written down and the fix is tracked until it is done.
Security questions: security@meetleady.com · Privacy questions: privacy@meetleady.com
Questions about compliance and documents
See all questionsDo you sign a BAA, and when?
Yes, before any call is answered or any practice data is touched. One standard BAA covers every license, with no per-practice variants.
Where is our data hosted?
On AWS, in a United States region, under our Business Associate Addendum with AWS. Every supplier we use is named in the table on this page, with what it sees.
Is data encrypted?
Connections to our database are encrypted and verified, and database storage is encrypted. Encryption rules for stored files are being set up; no files are stored yet.
What do you read from our PMS?
Appointments, chairs, providers, appointment types, and the patient details booking needs. Never clinical notes, imaging, ledgers, payments or payroll.
Do you record calls?
Not today. Audio is off in every state until counsel clears that state. Calls are transcribed, and the caller is told so at the start.
Who at Leady can see our data?
Nobody day to day. When something goes wrong, access goes in logged steps, one call at a time. Nobody at Leady plays call audio: the database refuses it.
How do our staff sign in?
Each person has their own invitation-only account. Today the portal separates administrators from staff; two-step sign-in, per-role settings and the 15-minute idle sign-out are being built.
Do you have a SOC 2 report?
No. We are not certified. We plan the audit after our first practices go live.
Have you had a penetration test?
Not yet. We have not had a third-party penetration test, and we say so until we have.
How quickly will you tell us about a breach?
A first notice within 10 calendar days of discovery, under our BAA, with details added as we learn them.
What happens to our data if we leave?
Calls stop on the termination date. A 30-day transition lets you export your data, and on request we send a copy and delete ours.
Do you use our calls to train AI?
No. Nothing derived from your calls leaves your practice's account, our AWS organization has the AI-services opt-out set, and the optional clause that would let a supplier use our content to improve its services is off.