Third Party Index

Snapshot 49011

Document
Security page
URL
https://www.lippy.ai/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
127045 bytes
SHA-256 (raw)
684c6930d6e2e1faf800c439d35c19293f08e4ac1ea173bc4feab14373944647
SHA-256 (normalized text)
5933067e29fbb81528e84a21c48456a1c650337c7d35ae7c4fb0eeb210d7baac

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Lippy AI
Log In
Lippy AI
Trust & Security
Enterprise-gradetrust,builtforregulatedindustries
Lippy handles real customer conversations for healthcare, home services, and other businesses where security isn't optional. Here's exactly how we protect your data and your callers.
See compliance status
How we protect your data
Security is engineered into the platform, not bolted on. These are the controls in place today.
HIPAA-compliant healthcare offering
For healthcare customers, Lippy offers a HIPAA-enabled environment designed to process protected health information separately from standard customer workloads.
Encryption in transit and at rest
All traffic to and from Lippy is encrypted in transit over TLS. Customer data is encrypted at rest. Third-party integration credentials are stored encrypted.
Access controls and least privilege
Access to customer data is scoped by organization and role (owner, admin, member, viewer), enforced server-side. Internal access follows least-privilege principles, with multi-factor authentication required for administrative accounts and infrastructure access.
AI transparency
Callers are told they're speaking with an AI assistant. We believe disclosure is the right default for conversational AI, and we build our agents to be upfront that the voice on the line is Lippy's AI.
Data handling and retention
Customer data is logically separated by organization. Data is retained to operate the service and is deleted in line with our agreements and applicable retention obligations. Our subprocessors are vetted and published, and a Data Processing Agreement is available.
Credential and secret management
Application secrets and integration tokens are managed through a centralized secrets store with rotation procedures, never committed to source control. Production access is gated and audited.
Compliance status
We're transparent about where we are. We only claim what's true today.
HIPAACompliant offering · BAA available
Available to healthcare customers under an executed BAA with HIPAA features enabled.
Continuous monitoringActive
Infrastructure, dependency, and vulnerability monitoring run continuously across our cloud accounts.
DPA & subprocessorsPublished
A Data Processing Agreement and a current list of subprocessors are publicly available.
Policies & documentation
Privacy PolicyData Processing AgreementSubprocessorsTerms of Service
Have a security or compliance question?
Our team is happy to walk through our architecture, sign a BAA, or answer your security questionnaire.