Trust & security

Care is sacred. We treat your data like it is.

HIPAA-compliant. SOC 2 Type II audited. Encrypted at rest and in transit. We never sell your data, and we never train AI on identifiable session content.

Listening, attentively
HIPAA

HIPAA-compliant by design

End-to-end encrypted messaging. Audit logs on every PHI access. Minimum-necessary by default.

SOC 2

SOC 2 Type II

Audited annually by an independent third party. Reports available under NDA.

BAA

BAA on request

Standard BAA available for orgs and self-employed practitioners. We've signed hundreds.

AES-256

Encryption everywhere

AES-256 at rest, TLS 1.3 in transit. Customer-managed keys for enterprise plans.

US-only

US data residency

All PHI stored and processed in US-based, HIPAA-eligible cloud regions. EU residency on roadmap.

AI policy

AI you can audit

Lily Coach uses HIPAA-eligible LLM endpoints. We never train on identifiable session content. Members can opt out.

RBAC

Role-based access

Granular roles for org admins, billing, comms. Just-in-time clinician access. Full audit log.

Privacy

Privacy as default

Members opt in to share, not out. De-identified by default in all org-side analytics.

Crisis

Crisis safety net

988 routing always one tap away. Lily Coach detects risk and escalates to human support 24/7.

Crisis resources

Help is always one tap away.

Lily's crisis routing is free, on every plan, for every user — no login required.

988

Suicide & Crisis Lifeline

Call or text 988 (US). Available 24/7 in English and Spanish. Chat at 988lifeline.org.

Call 988
741741

Crisis Text Line

Text HOME to 741741 to connect with a trained crisis counselor. Free, 24/7, confidential.

Text HOME
911

Emergency services

For immediate danger to yourself or others. Lily coordinates with emergency responders when needed.

Call 911

Security questions? We have answers.

Our team will share our SOC 2 report, BAA, security questionnaire, and DPA on request.