Security
Client data, treated like clinical data.
Med spas trust Tepali with the most sensitive information they hold — health histories, clinical photos, charts, and payment records. Protecting it is a product requirement, not a policy document.
HIPAA compliance
Tepali is built for protected health information. Charts, photos, and client records are handled under HIPAA safeguards, and we sign Business Associate Agreements with the practices we serve.
SOC 2
Our security controls — access management, change management, monitoring, and incident response — are governed by the SOC 2 framework.
Encryption everywhere
Data is encrypted in transit with TLS and at rest in the database, including client records, messages, and clinical documentation.
Access control
Role-based permissions govern what every team member can see and do, and practice data is isolated per tenant at the database layer.
Payments never touch our servers
Card data is processed end to end by Stripe, a PCI Level 1 service provider. Tepali never stores card numbers.
AI with guardrails
Tepali's AI employee operates inside the same permission system as your staff — it can only see the data your practice already holds, and every action it takes is logged.
Questions about our security practices, or need documentation for your review? Ask us directly — we’ll walk you through it.
HIPAA compliant · SOC 2