The trust you build with clients is sacred. Any technology in your practice should protect that trust—not complicate it, not compromise it.
Nesso is built specifically for mental health professionals, with privacy, consent, and ethical care at the center of how we design and secure the product.
Nesso is audited by VanRein Compliance, an independent HIPAA compliance firm. As your HIPAA Business Associate, we provide a BAA at onboarding and are required to safeguard PHI according to HIPAA rules.
We don’t sell your data, your clients’ data, or your usage data. Not now, not ever.
Session and dictation audio is deleted the moment it's transcribed, and transcripts delete themselves within 30 days.
Your session audio, transcripts, and clinical documents are never used to train AI.
We choose partners who meet strict privacy and safety standards, and carefully control how these services interact with your data.
Used to generate notes and documentation
Used to transcribe audio into text
AI drafts. You review. Nothing goes in the chart until you approve it.
Transcripts delete automatically within 30 days. You can delete them sooner with one click.
Record a full session or dictate a short recap. AI only processes the information you choose to share in that workflow.
Clear, simple flows reduce the chance of accidental oversharing or PHI exposure. Fewer steps mean fewer opportunities for something to go wrong.
Every feature is designed to support your judgment, not override it. You stay in control of what’s captured, what’s stored, and what’s deleted.
Multi‑factor authentication adds an extra layer of protection to your account, so only you can access your workspace.
Your data is encrypted at rest (AES‑256) and in transit (TLS 1.2+), keeping PHI protected whether it’s stored or moving through the system.
All data is stored and processed in the United States, with strict access controls and monitoring.
Session and dictation audio is deleted as soon as it’s transcribed. Sensitive recordings never sit on our servers.
Yes. Nesso is independently audited for HIPAA compliance by VanRein Compliance, an independent HIPAA compliance firm.
Yes. Every Nesso customer receives a Business Associate Agreement (BAA) at onboarding. It's our HIPAA commitment, in writing, to safeguard your clients' Protected Health Information.
Transcripts are stored for up to 30 days and then deleted automatically. You can delete them sooner at any time.
No. All recordings are deleted immediately after a transcript is generated.
No. We do not allow external AI providers to train their models on your data.
All data is stored and processed in the United States, with encryption at rest and in transit.