Security at Harbor

Updated September 11, 2026

Harbor handles sensitive practice and patient information. Our work combines technical controls, operating policies, and verification of how those safeguards perform. This page describes that work; it is not an independent security assessment or certification of legal compliance.

Identity and access

The application uses AWS Cognito for workforce identity and includes authenticator-app MFA, session timeout, role-based permissions, and practice-level data scoping. MFA enrollment, recovery paths, and authorization coverage require verification for the accounts and workflows in use. Our policy requires least privilege, prompt revocation, and quarterly access reviews; completed reviews are documented separately.

Encryption and storage

The AWS architecture uses managed encryption for the database and protected storage, TLS for transport, and restricted network access. Storage, backups, keys, and vendor services each require configuration verification. Encryption does not prevent an authorized or compromised account from accessing decrypted information.

Audit and monitoring

Application audit records capture instrumented events with context such as actor, time, and target. Protected archive and cloud monitoring mechanisms support investigation. We verify coverage by workflow and track gaps; infrastructure logs alone do not record every clinical access. Retention and archive settings must be checked separately from event coverage.

Backups and recovery

Our continuity policy specifies encrypted backups, point-in-time recovery, cross-region recovery protections, and quarterly restore exercises. Recovery objectives depend on the incident and verified backup configuration. A dated restore exercise supports the scope tested on that date; it is not a guarantee of uninterrupted service or zero data loss.

Workforce and change management

Documented policies require training before PHI access and annually thereafter, secure workstations, risk review, incident handling, and controlled releases. Application changes are tested in a separate environment before the specific release is promoted. Policies describe requirements; review records, test results, and configuration evidence establish performance.

AI and patient safety

Clinical documentation outputs are drafts for clinician review. Scheduling and other administrative communications may be automated. Receptionist call handling is distinct from therapy sessions; Harbor does not offer therapy-session recording. Safety signals support practice response and do not replace clinical judgment. Harbor is not an emergency service. The receptionist is configured to provide a 988 referral during the call. Screening includes escalation fallbacks, but this does not guarantee detection or delivery. Phone transcript analysis that produces a clinician alert occurs after the call ends; it is not live clinician monitoring. Optional clinical-AI choices do not necessarily disable receptionist or safety functions.

Assessment work

We are systematically verifying our safeguards and aligning our disclosures with the product. Funding will support independent security assessment and specialist legal review. Harbor has not completed a third-party SOC 2 examination; cloud-provider reports do not constitute a Harbor report.

Agreements and incident response

A practice BAA is required before PHI processing. Our BAA sets contractual duties; our HIPAA page identifies vendor roles. Incident notices follow the executed agreement and applicable law, without unreasonable delay. Existing signed commitments remain in force under their terms even when a public description is revised.

Request information or report a concern at chance@harboroffice.ai. Please omit patient information and credentials from an initial message.