
Psynth is SOC 2 Type 2 compliant, with a clean report
Psynth's SOC 2 Type 2 audit came back with zero exceptions. Built for clinical data with HIPAA, PIPEDA, and GDPR assessments and zero retention.
Psynth is SOC 2 Type 2 compliant, with a clean report
Psynth has completed its SOC 2 Type 2 audit, and the final report came back with zero exceptions.
For the psychologists, practice owners, and compliance teams who trust us with client data, this is independent proof that the safeguards we talk about are real, tested, and working.
What SOC 2 Type 2 means
SOC 2 is a security framework developed by the AICPA. An independent auditor examines how a company protects customer data and reports on what it finds.
There are two levels:
- Type 1 confirms that security controls are designed correctly at a single point in time.
- Type 2 goes further. The auditor tests whether those controls actually operated as intended over a period of several months.
Type 2 is the higher bar, and enterprise buyers, health systems, and school districts increasingly ask for it.

Why a clean report matters
When an auditor finds a control that didn't work as described, they record it as an exception. Many companies pass SOC 2 with a few.
Psynth had none. Every control tested held up for the full audit period.
That includes the day-to-day work that keeps data safe:
- Encryption of data at rest and in transit
- Multi-factor authentication and quarterly access reviews
- Continuous logging, monitoring, and intrusion detection
- Regular penetration testing and vulnerability scanning
- Tested backups across multiple availability zones
- Documented incident response and staff HIPAA training
Built for clinical data from day one
SOC 2 Type 2 adds to a compliance foundation that was already in place:
- HIPAA, PIPEDA and GDPR assessments completed by Assured Information Solutions (AIS)
- Zero-retention architecture, so client data isn't stored after processing
- Test-by-test report structure, which keeps each client's information separate
- ISO 27001, currently in progress
Psychologists are responsible for protecting their clients' confidentiality, no matter which tools they use. Our job is to make that responsibility easier to meet, not harder.

What this means for you
If you're a solo practitioner, you can use Psynth knowing an independent auditor has verified how you handle client data.
If you run a group practice or organization, you now have the documentation your IT and compliance teams need to approve Psynth, without weeks of back-and-forth security questionnaires.
If you already use Psynth, your workflow won't change. You get the same V1 drafts and the same control over every report, now backed by a clean SOC 2 Type 2 report.
Get the report
Our SOC 2 Type 2 report, along with our HIPAA, PIPEDA, and GDPR reports, is available on request at trust.psynth.ai. You'll also find our full list of security controls, policies, and subprocessors there.
Thank you to our team for the work behind this, and to the clinicians who trust Psynth with their most sensitive work. We don't take that lightly.
Book a demo or start your free trial to see Psynth in action.
Frequently Asked Questions
Can I regenerate only part of a report?
Yes. You can regenerate an individual section or select multiple sections when you want to apply the same instruction to them. Regenerated text remains draft material that requires psychologist review and editing.
Does Psynth's AI store patient data?
No. Psynth uses a zero-retention architecture. Patient data is tokenized during processing and is not stored, cached, or used for model training. Each report operates in an isolated environment.
How do I start using Psynth?
Start a free trial directly in the Psynth app, then email support@psynth.ai to redeem the AU and NZ pricing offer.
What is the primary tool psychologists use?
The primary tool psychologists use is psychological assessment instruments, which cover standardized tests, self-reflection questions, and behavioral evaluations. These help clinicians diagnose mental health conditions, plan treatment, monitor progress, and conduct research.
Where can I review Psynth's security policies?
All policies, controls, and certification documentation are publicly available at trust.psynth.ai.







