Security

Designed for trust from day one

Security is not a feature layered on later at Leitara. It is a foundational design constraint.

Leitara is built to support sensitive clinical work, and we design our systems to minimize risk, limit exposure, and protect trust—without adding unnecessary complexity for clinicians or clients.

Our security principles

We design Leitara around a small set of guiding principles:

  • Least privilege – access is limited to what is strictly necessary
  • Compartmentalization – systems and data are segmented to reduce blast radius
  • Encryption by default – data is protected in transit and at rest
  • Minimal data footprint – we collect and retain only what is required
  • Operational restraint – fewer moving parts means fewer failure modes

Security, like efficiency, works best when it is quiet.

Data protection

Encryption

  • Data is encrypted in transit using industry-standard TLS
  • Data is encrypted at rest using modern encryption standards
  • Encryption keys are managed securely and access-controlled

Access controls

  • Role-based access controls (RBAC)
  • Principle of least privilege enforced across systems
  • Administrative access is tightly restricted and audited

Data isolation

  • Logical separation between organizations and users
  • Compartmentalized services to limit cross-system exposure
  • Clear boundaries between application layers

HIPAA

Leitara is designed to support HIPAA-compliant workflows.

Where applicable:

  • We operate as a service provider to covered entities
  • Protected health information (PHI) is handled in accordance with HIPAA requirements
  • Administrative, technical, and physical safeguards are implemented to protect PHI
  • A Business Associate Agreement (BAA) is available upon request

Clinicians and practices remain responsible for their professional and regulatory obligations.

Infrastructure and operations

Leitara is hosted on modern, reputable cloud infrastructure with strong physical and operational security controls.

Operational practices include:

  • Secure configuration management
  • Regular system updates and patching
  • Monitoring for availability, performance, and security events
  • Controlled deployment and change management processes

We prioritize stability and predictability over rapid, risky change.

Monitoring and auditing

We maintain logging and monitoring appropriate to the sensitivity of the system, including:

  • Authentication and access events
  • System health and error conditions
  • Security-relevant operational signals

Monitoring is used to protect the Service—not to profile users or clients.

Incident response

Despite best efforts, no system can eliminate all risk.

Leitara maintains procedures to:

  • Detect and respond to security incidents
  • Contain and mitigate impact
  • Notify affected parties as required by law or agreement
  • Review and improve safeguards following incidents

Data minimization and retention

We intentionally limit:

  • what data is collected
  • how long it is retained
  • who can access it

Clinical data remains under the control of the clinician or practice and can be managed in accordance with applicable agreements and legal requirements.

Third-party services

Where third-party services are used to support infrastructure or operations:

  • Providers are selected for security and reliability
  • Access is restricted to what is necessary
  • Data handling is governed by contractual obligations consistent with this security posture

We do not use third-party services for advertising or behavioral tracking.

What we don't do

To be explicit, Leitara does not:

  • sell or monetize data
  • run advertising or tracking networks
  • scrape or analyze content for marketing purposes
  • share data outside the scope of providing the Service

Responsible disclosure

We appreciate responsible disclosure of potential security issues.

If you believe you have identified a vulnerability, please contact us at:

security@leitara.com

We will review reports promptly and handle them responsibly.

Questions?

We understand that security requirements vary by practice and context.

If you have questions about Leitara's security posture, BAAs, or compliance alignment, we're happy to discuss them.

Contact: security@leitara.com

Security is not about adding friction.

It's about removing uncertainty.