Security & compliance
Built for practices that handle patient information
An AI front desk hears the same things your front desk does. Della treats every call as protected health information and is engineered accordingly.
Business Associate Agreement
Patient calls contain protected health information by default — names, treatments, medical history. We sign a BAA with every practice at pilot kickoff, before Della takes a single live call. No BAA, no go-live.
Encrypted everywhere
All traffic is encrypted in transit with TLS, and every record — transcripts, appointments, contact details — is encrypted at rest (AES-256) in our database layer.
Per-practice isolation
Every table in our database enforces row-level security scoped to your practice. Your data is isolated from every other workspace by the database itself — not just by application code.
Credentials never reach the browser
Calendar and integration tokens live in server-only tables with deny-all access policies. They are used exclusively by our backend and are never sent to any client.
Humans for the calls that need them
Della is built to know what it shouldn't handle. Emergencies and sensitive situations escalate to your on-call staff by your rules — configured per practice, never improvised.
Minimal, named subprocessors
We run on a short list of vetted infrastructure providers for hosting, database, voice, and calendar sync — shared with you in writing as part of your BAA, along with our data-retention and call-recording disclosure practices.
Evaluating vendors? Ask us the hard questions.
Where recordings are stored, how long transcripts are retained, which subprocessors touch PHI, how two-party-consent states are handled — we'd rather answer in writing before you connect a single call. Email hello@dellahq.com and we'll send our security overview and a BAA template the same day.