The open-source clinical record system lets customers inspect the code that stores sessions, notes, and patient records. Pablo's hosted inbox service is not open source. View the clinical system on GitHub →
Pablo limits production data flows to documented providers. Services that handle PHI are covered by a BAA; services without a BAA do not receive PHI. The machine-readable vendor manifest is maintained in the public repository.
| Provider | Purpose and data | BAA |
|---|---|---|
| Google Cloud | PHI storage, compute, Vertex AI inference, authentication, and telemetry | Yes |
| AssemblyAI | Optional transcription of recorded sessions on managed deployments | Yes |
| Plunk | Transactional email containing a user email address and reminder type; no patient identifiers or clinical content | Not required; no PHI |
| Stripe | Subscription and payment processing; no clinical content | Not required for financial transactions |
| Connected EHR | Read-only import of practice-authorized patient and calendar data from SimplePractice or Sessions Health | Your EHR agreement and Pablo's BAA cover the respective data flows |
Encryption, tenant isolation, MFA, AI processing, audit logging, backups, retention, and outbound-network controls are described on the technical implementation page →
Pablo runs an authorized internal penetration test against the deployed application each week. Testing covers the web application and API, tenant isolation, audit logging, dependency vulnerabilities, and unexpected outbound data flows.
The methodology draws from OWASP ASVS Level 2, the OWASP API Security Top 10, NIST SP 800-115, and the HIPAA Security Rule. Findings are tracked internally through remediation. Detailed reports are shared with customers and auditors on request at security@pablo.health; weekly results and live exploit details are not published.
The testing methodology and tooling remain public. Operators of self-hosted deployments can run the same tests against systems they own or are authorized to assess.
Confirmed incidents affecting customer data are investigated, contained, and communicated according to Pablo's BAA and applicable federal and state notification requirements. Customers receive the information needed to understand the impact and take action.
Security vulnerabilities are handled through coordinated disclosure. We notify affected operators privately, make a fix available, and publish a security advisory when public disclosure helps customers protect their deployments. Details that would create unnecessary risk may be withheld until patches are in place.
Organizations that run Pablo on their own infrastructure are responsible for securing that deployment and meeting their own breach-notification obligations.
Email security@pablo.health with the affected component, steps to reproduce, and your preferred name or attribution. Please avoid accessing data that is not your own or continuing beyond what is necessary to demonstrate the issue.
We aim to acknowledge reports within 72 hours. Pablo does not currently offer a paid bug bounty.