Third Party Index

Snapshot 19604

Document
Security page
URL
https://www.eckohealth.ai/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
54158 bytes
SHA-256 (raw)
e0bfe7222a743102a9774791efb113f3aedcad42614e0274008568c2d9518577
SHA-256 (normalized text)
8a8f63a85521a6065d29456b0f096535d5271f8bda318c3d695aba96128937fe

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Healthcare Data Security at Ecko
We treat patient data like it's our own.
Built by psychologists who understand what's at stake.
"Every design decision at Ecko starts with one question: Would I trust this with my own patient's data?"
— Marika Conomos. CEO, Founder & Psychologist
Most health platforms treat security as a compliance checkbox. We built Ecko around the belief that if you're handling someone's most vulnerable moments, security has to be architectural — not an afterthought.
Certifications & Compliance
ISO/IEC 27001
Controls implemented - formal certification underway
SOC 2
Controls implemented - formal certification underway
TGA
'Ecko for Patients' Care app is a TGA registered medical device. ARTG 527352
Australian Privacy Principles
Compliant
HIPAA
Aligned
Infrastructure
Google Cloud Platform (Sydney) — ISO 27001, 27017, 27018, SOC 2, IRAP PROTECTED
Payments: Stripe & Tyro — PCI DSS Level 1
View our Trust Portal
How we protect your data
Data Residency
All clinical data is stored exclusively in Australia on Google Cloud Platform's Sydney region, using IRAP
PROTECTED infrastructure with enforced data residency
via Assured Workloads.
Encryption
AES-256 encryption at rest. TLS 1.2+ in transit. Customer-managed encryption keys. Cell-based tenant isolation ensures no practice can ever access another's data.
AI & Privacy
Your clinical data is never used to train AI models. AI processing occurs via API under zero-data-retention agreements, so nothing is retained by the AI provider.
Ecko Health does not record or store session audio. Transcripts and clinical notes are stored in Australia and retained in line with clinical record-keeping obligations.
Payment Security
Payments are processed by Stripe and Tyro, both PCI DSS Level 1 certified. Ecko never stores, processes, or has access to card data directly.
Access Control & Monitoring
Role-based access controls, audit logging, and active monitoring. Every access to patient data is logged
and reviewable.
Business Continuity
Automated backups, 2-hour recovery time objective, and disaster recovery plans tested regularly.
FAQ
Is Ecko ISO 27001 certified?
Our infrastructure (GCP) is fully ISO 27001 certified. We have implemented ~90% of ISO 27001 controls ourselves and are pursuing our own independent certification — we are currently selecting our certification auditor.
Where is my data stored?
All clinical data is stored in Sydney, Australia on IRAP PROTECTED infrastructure.
Is Ecko HIPAA compliant?
Ecko is HIPAA aligned. We serve a small number of US-based users and our controls meet HIPAA requirements.
Is my data used to train AI?
No. Your data is never used for AI training.
What happens if there's a data breach?
We have an incident response plan with a fixed time notification commitment. Details in our Trust Portal.
Can I get a DPA or BAA?
Yes. Contact us at [email protected]
Enterprise Readiness
- DPA and BAA available on request
- Customer audit rights
- Dedicated account management
- Custom onboarding and data migration
- SLA: 99.9% uptime for enterprise plans
Contact us for enterprise security documentation
Contact us