> ## Documentation Index
> Fetch the complete documentation index at: https://docs.heyrafiki.space/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and privacy

> What Heyrafiki protects, how access is decided, and what never leaves.

Access is decided by three things together: the role of the person asking, the purpose of the request, and the Consent attached to the record. Any one of them failing denies the request.

## Core principles

* Collect only what a workflow needs.
* Store identity data apart from clinical data.
* Scope every sensitive access, and write it to an audit trail.
* Let People decide what is shared, and with whom.
* Keep private Care content out of product analytics entirely.

## In transit

Every response is served over HTTPS with HSTS. Browsers are told to refuse framing, ignore MIME sniffing, send a lean referrer and keep device permissions limited to what a Session needs.

## Clinical boundaries

Iris may draft Clinical Notes, but a Practitioner must review and approve them before they become part of the approved record.

## Organization access

Organizations receive aggregate reporting for the Programs they fund. Those reports never include a Person's identity, diagnosis, Session content or private Conversation.

## What Iris learns from

Iris improves from whether a suggestion was accepted, edited or dismissed. She does not learn from Session content, Messages, Journals or Check answers, and those are never used to train product models, regardless of any setting.

## Reporting a vulnerability

Send security concerns to [hello@heyrafiki.space](mailto:hello@heyrafiki.space). Do not include passwords, keys or clinical records in a first message. We acknowledge reports and agree a fix and disclosure timeline with the reporter.
