Psynth is SOC 2 Type 2 compliant, with a clean report

Psynth's SOC 2 Type 2 audit came back with zero exceptions. Built for clinical data with HIPAA, PIPEDA, and GDPR assessments and zero retention.

Author
Reviewed By

Psynth is SOC 2 Type 2 compliant, with a clean report


Psynth has completed its SOC 2 Type 2 audit, and the final report came back with zero exceptions.


For the psychologists, practice owners, and compliance teams who trust us with client data, this is independent proof that the safeguards we talk about are real, tested, and working.
‍

What SOC 2 Type 2 means


SOC 2 is a security framework developed by the AICPA. An independent auditor examines how a company protects customer data and reports on what it finds.


There are two levels:
‍

  • Type 1 confirms that security controls are designed correctly at a single point in time.
    ‍
  • Type 2 goes further. The auditor tests whether those controls actually operated as intended over a period of several months.

Type 2 is the higher bar, and enterprise buyers, health systems, and school districts increasingly ask for it.
‍

Psynth is SOC 2 Type 2 compliant

‍

Why a clean report matters


When an auditor finds a control that didn't work as described, they record it as an exception. Many companies pass SOC 2 with a few.
‍
Psynth had none. Every control tested held up for the full audit period.
‍

That includes the day-to-day work that keeps data safe:
‍

  • Encryption of data at rest and in transit
    ‍
  • Multi-factor authentication and quarterly access reviews
    ‍
  • Continuous logging, monitoring, and intrusion detection
    ‍
  • Regular penetration testing and vulnerability scanning
    ‍
  • Tested backups across multiple availability zones
    ‍
  • Documented incident response and staff HIPAA training
    ‍

Built for clinical data from day one


SOC 2 Type 2 adds to a compliance foundation that was already in place:
‍

  • HIPAA, PIPEDA and GDPR assessments completed by Assured Information Solutions (AIS)

  • Zero-retention architecture, so client data isn't stored after processing
    ‍
  • Test-by-test report structure, which keeps each client's information separate
    ‍
  • ISO 27001, currently in progress

Psychologists are responsible for protecting their clients' confidentiality, no matter which tools they use. Our job is to make that responsibility easier to meet, not harder.

‍

Psychological Report Writing Software | Psynth

‍

What this means for you


If you're a solo practitioner,
you can use Psynth knowing an independent auditor has verified how you handle client data.
‍

If you run a group practice or organization, you now have the documentation your IT and compliance teams need to approve Psynth, without weeks of back-and-forth security questionnaires.
‍

If you already use Psynth, your workflow won't change. You get the same V1 drafts and the same control over every report, now backed by a clean SOC 2 Type 2 report.
‍

Get the report


Our SOC 2 Type 2 report, along with our HIPAA, PIPEDA, and GDPR reports, is available on request at trust.psynth.ai. You'll also find our full list of security controls, policies, and subprocessors there.
‍

Thank you to our team for the work behind this, and to the clinicians who trust Psynth with their most sensitive work. We don't take that lightly.
‍

Book a demo or start your free trial to see Psynth in action.

Frequently Asked Questions

Can I regenerate only part of a report?

Yes. You can regenerate an individual section or select multiple sections when you want to apply the same instruction to them. Regenerated text remains draft material that requires psychologist review and editing.

Does Psynth's AI store patient data?

No. Psynth uses a zero-retention architecture. Patient data is tokenized during processing and is not stored, cached, or used for model training. Each report operates in an isolated environment.

How do I start using Psynth?

Start a free trial directly in the Psynth app, then email support@psynth.ai to redeem the AU and NZ pricing offer.

What is the primary tool psychologists use?

The primary tool psychologists use is psychological assessment instruments, which cover standardized tests, self-reflection questions, and behavioral evaluations. These help clinicians diagnose mental health conditions, plan treatment, monitor progress, and conduct research.

Where can I review Psynth's security policies?

All policies, controls, and certification documentation are publicly available at trust.psynth.ai.

See Psynth work in real time

We’ll demo an end-to-end report writing process and answer any questions along the way. (Yes, it’s so quick, we can get through it all during a single call.)
Book a Demo ->