Trust
Security and Compliance
The frameworks that apply to Saalvio
- PHIPA
- Personal Health Information Protection Act, Ontario. Governs how we handle therapy records for Ontario residents.
- PIPEDA
- Personal Information Protection and Electronic Documents Act, federal Canada. Governs commercial handling of personal information.
- HIPAA-aligned
- US Health Insurance Portability and Accountability Act. Our US infrastructure for Thrive AI (our CBT chatbot) and for our separate guided CBT self-help tools, calming music, and cognitive games runs under signed Business Associate Agreements. A formal HIPAA audit is scheduled for our US psychotherapy expansion.
- AODA
- Accessibility for Ontarians with Disabilities Act. The public site meets WCAG 2.1 Level AA.
- Law 25 (Quebec)
- Under evaluation. Saalvio does not currently operate in Quebec. A formal Law 25 assessment is part of our Phase 2 Quebec expansion.
- Regulator standards
- Our clinicians practise under their regulator's standards: the College of Registered Psychotherapists of Ontario for RPs, and the Ontario College of Social Workers and Social Service Workers for RSWs. Both colleges set binding records-management and confidentiality standards.
Technical safeguards
- Encryption in transit. Every connection to saalvio.com, our therapy platform (including pre-booking and between-session messaging with a therapist), Thrive AI, and our separate guided CBT self-help tools, calming music, and cognitive games uses TLS 1.2 or higher.
- Encryption at rest. Therapy records, messaging threads with a therapist, Thrive AI conversations, usage records from our separate wellness products, and backups are encrypted using industry-standard algorithms.
- Two-factor authentication. Mandatory for every Saalvio team member with access to client data or production systems.
- Named accounts only. No shared logins. Access is logged.
- Least-privilege access. Saalvio team members can see only the records they need to do their job.
- Vulnerability patching. Operating systems, frameworks, and dependencies are patched on a rolling schedule.
- Web application firewall and bot management at the edge.
- Daily backups, encrypted, retained per our retention schedule.
Administrative safeguards
- Privacy Officer accountable for PHIPA, PIPEDA, and HIPAA compliance.
- Documented information-security policies reviewed annually.
- Staff training on privacy and security before any production access.
- Confidentiality agreements with all staff and contractors.
- Business Associate Agreements with US vendors that handle protected health information.
- Vendor review before adding any new processor.
Incidents and breach notification
If we discover a security incident that poses a real risk of significant harm, we follow our incident-response plan. That includes containing the incident, investigating its scope, notifying affected individuals where required, and reporting to the relevant privacy regulators (the Information and Privacy Commissioner of Ontario, the Office of the Privacy Commissioner of Canada, or the US Office for Civil Rights).
Our incident-response plan is reviewed and rehearsed annually.
Thrive AI specifics
- Conversations are stored encrypted, in US-region cloud infrastructure governed by a signed Business Associate Agreement.
- Conversations are retained for 24 months by default. You can ask us to delete them sooner.
- Conversation data is not used to train third-party foundation models. Our underlying model providers have agreed contractually not to retain or train on the data they process on our behalf.
- Thrive AI detects high-risk content (suicidal thoughts, self-harm, harm to others) and surfaces the canonical crisis resources (911 for immediate danger, 988 the Suicide Crisis Helpline of Canada for mental health crisis, and the nearest emergency department) before stepping back from the conversation. This is a safety guardrail, not a clinical assessment.
For partners and B2B clients
If you represent a clinic, EAP, employer, school board, or other organization considering a referral or partnership with Saalvio, contact [email protected] or call (289) 963-9881. We can provide our standard data-processing terms, our incident-response summary, and our HIPAA / PHIPA risk-assessment summary on request, under a mutual non-disclosure agreement.
Questions about security and compliance
Email [email protected]. Our Privacy Officer routes questions to the right person on our team.