Security at Kintaria

Last updated: May 20, 2026 · Pre-launch posture

Kintaria holds health information about people in vulnerable moments. We take that seriously. This page documents what's in place today, what's coming, and where we're not yet — written for a family member who wants to know what they're trusting us with, not just for an auditor.

The short version: every piece of workspace data is gated by family membership at the database layer (not just in app code). Every mutation is audit-logged. Data is encrypted in transit and at rest. We don't sell data, run ads, or share workspace contents with anyone outside your invited family. We're not yet a HIPAA covered entity — see §7 below.

1. The controls in place today

2. Who can see what

Four roles inside a workspace, each with progressively narrower access. None of them can see other families' workspaces — that's a database-layer guarantee, not a policy.

Kintaria staff cannot read workspace contents in the normal course of operations. The privileged database role used for migrations and incident response is logged and bounded.

3. Where your data lives

All workspace data is stored in a single US-region Supabase project (database + storage). No cross-region replication. No CDN edge cache of workspace pages.

The marketing site (thrive.me) is hosted on Vercel and only serves static, non-personal content. The voice-line phone-number lookup runs on Fly.io.

4. Vendor list

Every third-party service that touches your data, and where each one stands on a BAA:

What “BAA available — in process” means: the vendor offers a Business Associate Agreement for HIPAA-covered organizations and we are in the process of executing one. Until those are signed and Kintaria itself is a covered entity, please don't upload anything you would need bound by a HIPAA contract. See §7.

5. AI features

AI features (visit summaries, document classification, lab-report extraction from photos) are off by default. The workspace owner has to explicitly turn them on in Settings → AI features. When off, no content from the workspace is sent to any AI service.

When on:

What AI doesn't do — ambient recording is not supported. Kintaria does not currently record audio in clinical or family settings. There is no “turn on the microphone in the doctor's office” feature in the app. If we ever add one, it will ship only after: a per-state all-party vs one-party consent rule engine (the 14 all-party states require affirmative consent from every participant); a mid-recording new-participant prompt that pauses the recording when a new voice is detected; a signed Business Associate Agreement with whichever vendor processes the audio; and one-tap revoke that propagates to vendor-side deletion within 7 days. The internal spec for that bar lives in RECORDING_CONSENT_SPEC.md. We mention all of this publicly because the question gets asked and we'd rather pre-empt the ambiguity than let people guess.

6. Sharing with providers

Treat the URL like a one-time password. For sensitive recipients, send via a portal message or by phone rather than open SMS.

7. HIPAA posture — stated plainly

Kintaria is not yet a HIPAA covered entity. We are pre-launch and not yet under Business Associate Agreements with every vendor that touches workspace data.

The architecture is built to HIPAA-aligned controls (audit logging, encryption, access control, minimum-necessary disclosure, secure development practices). A formal BAA framework, a Notice of Privacy Practices, and the operational policies HIPAA requires are all on the pre-launch readiness path. Until those are complete, please don't upload anything you would need bound by a HIPAA contract today.

Texas Responsible AI Governance Act (TRAIGA, effective January 1, 2026). Texas now requires licensed healthcare practitioners to give patients conspicuous written disclosure of any AI use in diagnosis or treatment. Kintaria's AI features (visit summaries, lab extraction, document tagging) are off by default and require explicit per-feature opt-in by the workspace owner — designed so a Texas clinician reviewing notes a family caregiver brings in can accurately disclose AI involvement when they need to.

HHS HIPAA Security Rule update (final rule expected late 2026). The proposed rule would mandate encryption of ePHI in transit and at rest (already in place at Kintaria), MFA for critical and remote systems (we offer optional two-step sign-in today), and explicit handling requirements for AI systems touching patient data (written inventories, ongoing vulnerability monitoring). Our existing posture aligns with most of the proposed controls; we'll update this section as the final rule lands.

8. Data retention & deletion

Workspace data is retained as long as the workspace exists. When you delete a workspace:

9. Reporting a security issue

Email security@thrive.me (alias to info@) or call (888) 704-0999. We acknowledge within one business day. No formal bug bounty yet; good-faith reporters acknowledged publicly with permission.

10. Operational practices

11. Coming next

12. Questions

Email info@thrive.me or call (888) 704-0999. We answer every message.