Safe, secure, and private

The trust you build with clients is sacred. Any technology in your practice should protect that trust—not complicate it, not compromise it.

Nesso is built specifically for mental health professionals, with privacy, consent, and ethical care at the center of how we design and secure the product.

HIPAA Compliant BadgePrivacy Protected Badge

The basics

HIPAA compliant and independently audited

Nesso is audited by VanRein Compliance, an independent HIPAA compliance firm. As your HIPAA Business Associate, we provide a BAA at onboarding and are required to safeguard PHI according to HIPAA rules.

Your data isn’t for sale

We don’t sell your data, your clients’ data, or your usage data. Not now, not ever.

Recordings never stick around

Session and dictation audio is deleted the moment it's transcribed, and transcripts delete themselves within 30 days.

Responsible approach to AI

We don't train on clinical content

Your session audio, transcripts, and clinical documents are never used to train AI.

Strict standards

We choose partners who meet strict privacy and safety standards, and carefully control how these services interact with your data.

Anthropic (Claude)

Used to generate notes and documentation

AssemblyAI

Used to transcribe audio into text

You approve every note

AI drafts. You review. Nothing goes in the chart until you approve it.

We keep security simple

Automated transcript deletion

Transcripts delete automatically within 30 days. You can delete them sooner with one click.

You decide what AI sees

Record a full session or dictate a short recap. AI only processes the information you choose to share in that workflow.

Designed to prevent mistakes

Clear, simple flows reduce the chance of accidental oversharing or PHI exposure. Fewer steps mean fewer opportunities for something to go wrong.

Built for clinical work

Every feature is designed to support your judgment, not override it. You stay in control of what’s captured, what’s stored, and what’s deleted.

How we protect your data

Secure sign in

Multi‑factor authentication adds an extra layer of protection to your account, so only you can access your workspace.

Strong encryption

Your data is encrypted at rest (AES‑256) and in transit (TLS 1.2+), keeping PHI protected whether it’s stored or moving through the system.

US-only storage

All data is stored and processed in the United States, with strict access controls and monitoring.

Immediate audio deletion

Session and dictation audio is deleted as soon as it’s transcribed. Sensitive recordings never sit on our servers.

The legal details

Privacy Policy
BAA
Certificate of Compliance
Last reviewed: July 2026

Frequently asked questions

Privacy and Security
Is Nesso HIPAA compliant?

Yes. Nesso is independently audited for HIPAA compliance by VanRein Compliance, an independent HIPAA compliance firm.

Do I get a BAA?

Yes. Every Nesso customer receives a Business Associate Agreement (BAA) at onboarding. It's our HIPAA commitment, in writing, to safeguard your clients' Protected Health Information.

How long are transcripts stored?

Transcripts are stored for up to 30 days and then deleted automatically. You can delete them sooner at any time.

Does Nesso store my session recordings?

No. All recordings are deleted immediately after a transcript is generated.

Can external AI companies train on my data?  

No. We do not allow external AI providers to train their models on your data.

Where is my data stored?

All data is stored and processed in the United States, with encryption at rest and in transit.

Ready to tackle your backlog?

Try for Free
Try new features first, including the EHR
We'll only email you about Nesso. Unsubscribe anytime.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.