Back to Legal Center
B2B Security Assessment

FaceofMind Technical Security & Compliance Brief

Document Class: B2B Security Architecture Review • Version: 1.0 • Effective: July 13, 2026 • Status: Active

Enterprise & Clinical Information NoticeThis document provides a technical deep-dive into the security controls, encryption architectures, and compliance alignments of FaceofMind. It is specifically intended for hospital IT auditors, healthcare compliance officers, and enterprise partners.
Data Residency Options
PH, EU, US
Encryption At Rest
AES-256-GCM
Network Protection
TLS 1.3 + Pinning
Audit Log Model
Append-Only Tables

1. Cryptographic Architecture & Key Management

FaceofMind enforces field-level and storage-level encryption using industry-standard authenticated encryption. Our infrastructure utilizes Google Cloud Key Management Service (KMS) for secure key lifecycle administration.

Envelope Encryption Model

We protect sensitive data fields (such as patient identifiers, transcription values, and journal insights) using data encryption keys (DEKs). These DEKs are wrapped using key encryption keys (KEKs) administered dynamically inside the secure HSM boundaries of Cloud KMS.

Key Cycles & Rotation

Key encryption keys are automatically rotated every 90 days. Backed up data is cryptographically isolated on a per-tenant logical boundary to prevent any unauthorized cross-access or data correlation during migration events.

2. Administrative Controls & Audit Log Integrity

To align with HIPAA Administrative Simplification requirements and GDPR Accountability directives, our system implements detailed logs auditing the logs themselves ("Logs of Logs"). Security administrators, compliance officers, and database systems are audited.

Audit Log Interface Screenshots (GCP Logs & Portals)

Authentication Logs

Authentication Event Feed

Append-Only

Live Logs Feature: Identifies the user, success result, active service, client/device identifier, and source IP address. Hardened against modifications or tampering.

Clinical Data Access Logs

Psychologist Access Logs

HIPAA Aligned

Live Logs Feature: Tracks clinician name, exact scope accessed (e.g. Journal, Mood, Voice), access action status (VIEW/DENIED), and patient's explicit consent state.

🛡️ Session Timeouts: All administrative access sessions are governed by tokens that automatically expire within 60 minutes, limiting exposure to active workstation sessions.

3. Clinical Retention vs. Consumer Deletion

Healthcare providers face mandatory retention guidelines (usually 7 years for clinical notes) while consumers hold rights under the Right to be Forgotten. FaceofMind resolves this via data lifecycle segmentation:

Wellness Consumer Lifecycle

Mood logs, journal theme analysis, AI summaries, and voice templates can be deleted by the user directly via the app settings. Data is completely purged from all databases and offline backups within 30 days.

Clinical Care Archival

Clinical intake details, bookings, and psychologist diagnostic stamp notes are archived inside independent clinical database zones. These cannot be deleted by consumers and are retained for 7 years to support medical compliance guidelines.

4. B2B Infrastructure, SLA & Subprocessors

Single Sign-On & SAML

Enterprise Tier packages support SAML 2.0 and OpenID Connect (OIDC) protocols. This enables integrations with directory services (such as Okta, Azure AD, and Ping Identity) to enforce multi-factor authentication (MFA) and centralized login constraints.

Breach Notifications SLA

FaceofMind maintains an SLA guaranteeing regulatory and customer notifications within 72 hours of identifying a data breach. We conduct active incident responses managed by dedicated security personnel, providing post-incident reviews (PIR) to affected organizations.

Subprocessor Authorization List

SubprocessorProcessing PurposeData Categories
Google Cloud Platform (GCP)Database hosting, storage, KMS envelope servicesEncrypted PHI, logs, metadata
Stripe, Inc.B2B subscription invoice and payment processingBilling names, business cards, billing addresses
SendGrid / ResendSystem notifications, audit alerts, support mailingsAdministrative emails, security alerts
Sentry / DatadogError tracing, performance logging, system uptime trackingSystem metrics, anonymous crash stack traces

5. Verification & Security Audits

FaceofMind undergoes continuous security design alignments. Third-party penetration testing and infrastructure audits are conducted to identify potential vulnerabilities. Executive summaries of audits and security checklists are available to clinical partners under NDA.

Request Full Audit Records & Agreements

To sign a Business Associate Agreement (BAA), execute a Data Processing Agreement (DPA), or request administrative credentials for pre-revenue review, contact our enterprise compliance desk: