FaceofMind Technical Security & Compliance Brief
Document Class: B2B Security Architecture Review • Version: 1.0 • Effective: July 13, 2026 • Status: Active
1. Cryptographic Architecture & Key Management
FaceofMind enforces field-level and storage-level encryption using industry-standard authenticated encryption. Our infrastructure utilizes Google Cloud Key Management Service (KMS) for secure key lifecycle administration.
Envelope Encryption Model
We protect sensitive data fields (such as patient identifiers, transcription values, and journal insights) using data encryption keys (DEKs). These DEKs are wrapped using key encryption keys (KEKs) administered dynamically inside the secure HSM boundaries of Cloud KMS.
Key Cycles & Rotation
Key encryption keys are automatically rotated every 90 days. Backed up data is cryptographically isolated on a per-tenant logical boundary to prevent any unauthorized cross-access or data correlation during migration events.
2. Administrative Controls & Audit Log Integrity
To align with HIPAA Administrative Simplification requirements and GDPR Accountability directives, our system implements detailed logs auditing the logs themselves ("Logs of Logs"). Security administrators, compliance officers, and database systems are audited.
Audit Log Interface Screenshots (GCP Logs & Portals)
Authentication Event Feed

Live Logs Feature: Identifies the user, success result, active service, client/device identifier, and source IP address. Hardened against modifications or tampering.
Psychologist Access Logs

Live Logs Feature: Tracks clinician name, exact scope accessed (e.g. Journal, Mood, Voice), access action status (VIEW/DENIED), and patient's explicit consent state.
3. Clinical Retention vs. Consumer Deletion
Healthcare providers face mandatory retention guidelines (usually 7 years for clinical notes) while consumers hold rights under the Right to be Forgotten. FaceofMind resolves this via data lifecycle segmentation:
Mood logs, journal theme analysis, AI summaries, and voice templates can be deleted by the user directly via the app settings. Data is completely purged from all databases and offline backups within 30 days.
Clinical intake details, bookings, and psychologist diagnostic stamp notes are archived inside independent clinical database zones. These cannot be deleted by consumers and are retained for 7 years to support medical compliance guidelines.
4. B2B Infrastructure, SLA & Subprocessors
Single Sign-On & SAML
Enterprise Tier packages support SAML 2.0 and OpenID Connect (OIDC) protocols. This enables integrations with directory services (such as Okta, Azure AD, and Ping Identity) to enforce multi-factor authentication (MFA) and centralized login constraints.
Breach Notifications SLA
FaceofMind maintains an SLA guaranteeing regulatory and customer notifications within 72 hours of identifying a data breach. We conduct active incident responses managed by dedicated security personnel, providing post-incident reviews (PIR) to affected organizations.
Subprocessor Authorization List
| Subprocessor | Processing Purpose | Data Categories |
|---|---|---|
| Google Cloud Platform (GCP) | Database hosting, storage, KMS envelope services | Encrypted PHI, logs, metadata |
| Stripe, Inc. | B2B subscription invoice and payment processing | Billing names, business cards, billing addresses |
| SendGrid / Resend | System notifications, audit alerts, support mailings | Administrative emails, security alerts |
| Sentry / Datadog | Error tracing, performance logging, system uptime tracking | System metrics, anonymous crash stack traces |
5. Verification & Security Audits
FaceofMind undergoes continuous security design alignments. Third-party penetration testing and infrastructure audits are conducted to identify potential vulnerabilities. Executive summaries of audits and security checklists are available to clinical partners under NDA.
Request Full Audit Records & Agreements
To sign a Business Associate Agreement (BAA), execute a Data Processing Agreement (DPA), or request administrative credentials for pre-revenue review, contact our enterprise compliance desk: