Skip to content

Trust & security

Security for the work you trust us with.

A customer conversation. A clinical record. The next decision. ConnectX brings data protection, controlled access and human oversight to the work your teams do every day.

Discuss security requirements
ConnectX/Trust
Explore ConnectX safeguards

Protection around the record.

Saudi Arabia
Customer data hosted in the Kingdom.
Encrypted
In transit and at rest.
Private files
Restricted access. Short-lived links.
Explore the safeguards around your workflow.

01 / Data protection

Protect the information behind every interaction.

Business conversations and clinical records need protection as they move through a workflow and when they are stored.

Encryption in transit and at rest
Traffic uses HTTPS/TLS. Sensitive fields, including national IDs, insurance identifiers and credentials, receive an additional layer of authenticated AES-256 encryption before storage.
Private clinical files
Patient scans and documents are access-controlled and delivered through short-lived secure links. Patient files do not have permanent public URLs.
Hosted in Saudi Arabia
Customer data is hosted in Saudi Arabia. Our enterprise cloud foundation separates environments and uses managed, audited credential handling.

02 / Access and identity

The right context. For the right people.

Unified Memory connects context across agents and channels. Permissions define which information each role can use.

Separation between organizations
Each organization’s data is separated. Access within an organization is scoped by role, branch and function, with stricter rules for clinical information than administrative data.
Access by explicit permission
Access is denied by default and must be granted. A shared patient profile can support connected workflows while keeping clinical information subject to its access rules.
Protected sign-in
Credential protection, short-lived sessions and single sign-on support protect access. Login, password recovery and invitation flows are independently throttled to limit abuse.

03 / Privacy

Built around Saudi PDPL requirements.

Data handling is part of the workflow: what is collected, where it is used and how long it needs to remain.

Purposeful retention
Personal data is retained for the applicable regulatory and clinical requirements. Retention is limited to those needs.
A dedicated erasure process
Patient data-deletion requests are handled across the platform through a dedicated erasure process, subject to applicable retention requirements.
Less unnecessary exposure
Logs and internal tooling are designed to exclude sensitive personal content. External interfaces expose only the fields needed for their function.
Discuss your data requirements

04 / Human oversight

Clear responsibility, throughout the workflow.

AI can carry the work forward. The way it asks for help, learns from a resolution and presents work for review should be clear to the team using it.

AI Voice Agents

Bring a person into the decision.

Ask for guidance
With Soft Forwarding, the caller stays connected while the agent briefs a supervisor on a separate channel. The supervisor can guide the agent or ask to take over.
Learn from the resolution
The agent can stay on the call and listen to how a human resolves the issue. The Knowledge Loop scores learned solutions and automatically makes high-scoring solutions available for future calls.
Evaluate the whole outcome
Review the conversation, the escalation and what happened next. Test configuration changes against representative situations before release.
Explore a reviewed call

Clinical AI

Keep clinical judgment with the clinician.

Review the documentation
Medical Copilot develops the note from the consultation and patient context. The doctor reviews, corrects and approves the documentation.
Inspect the claim preparation
The insurance agent prepares billing codes, reasoning and an Integrity Score estimating acceptance likelihood. The billing team reviews and submits the claim; the score is not an acceptance guarantee.
Connect the next step
The consultation can trigger appointment outreach. Patient handouts are prepared for sharing, so the team can review what carries forward from the visit.
Explore a reviewed encounter

05 / Accountability

Accountability continues after the action.

Visibility into significant actions and control over changes support the day-to-day operation of the platform.

An audit trail for your organization
Significant actions record who acted, what happened, when and from where. Organization administrators can access this trail.
Continuous monitoring
Threat monitoring covers the application and infrastructure, with automated alerts operating around the clock.
Backups and controlled releases
Automated backups support resilience. Gated, controlled releases govern changes to the platform.

Your security review

Start with your workflow. Review the details together.

Before a rollout, bring your security, operational and clinical requirements into the same conversation. We can discuss the data flow, the people who need access and the decisions that require review.

Start a security conversation
  • Connected systems and data flows
  • Roles, branches and permissions
  • Retention and deletion requirements
  • Evaluation and human review

A closer look

Questions your team may ask.

Where is ConnectX data hosted?

Customer data is hosted in Saudi Arabia. For a proposed integration, discuss the complete data flow with our team, including the systems and providers connected to your workflow.

How is shared memory kept within access boundaries?

Unified Memory connects the customer or patient context across workflows. Organization separation and permissions by role, branch and function govern access. Clinical information has stricter rules than administrative data.

How are retention and deletion handled?

Personal data is retained for applicable regulatory and clinical needs. Patient deletion requests follow a dedicated platform erasure process, subject to applicable retention requirements. Discuss the requirements for your deployment with our team.

Who reviews clinical documentation and insurance claims?

The doctor reviews, corrects and approves the documentation. The insurance agent prepares codes, reasoning and an estimated acceptance likelihood for the billing team to review. The billing team submits the claim.

What should we review before a rollout?

Start with the workflow, the data it requires and the systems it connects. Then review access, retention, escalation and human responsibilities alongside representative evaluation cases. Use the security enquiry to share your requirements with our team.

Let’s talk about your requirements

Confidence starts with a conversation.

Bring the workflow you have in mind. We’ll walk through the controls and responsibilities around it.