Security & Compliance

Built for businesses that handle sensitive data.

Your customers trust you with personal information. Geckonaut treats that trust as the foundation of everything we build — with strong encryption, strict access controls, and infrastructure ready for the compliance requirements your industry demands.

The Foundation

Security that's built in — not bolted on.

256-bit AES Encryption

All data is encrypted at rest under the 256-bit Advanced Encryption Standard before it's ever written to disk.

Encrypted In Transit

Data moving between systems is protected with TLS encryption — secure from the moment it leaves the line.

Managed Key Rotation

Cryptographic keys are managed on hardened infrastructure, with each key itself encrypted under regularly rotated master keys.

HIPAA-Ready Infrastructure

The platform supports an account-wide HIPAA compliance package — available to activate for healthcare clients who require it.

BAA Available

When HIPAA compliance is enabled, a Business Associate Agreement is part of the package — handled during onboarding.

MFA Enforcement

When HIPAA is enabled, multi-factor authentication is enforced account-wide on every access point.

Audit Logging

Account activity is captured in audit logs — a clear, reviewable record of who did what and when.

Trusted Infrastructure

Built on enterprise-grade cloud infrastructure with the same hardened systems used to protect data at global scale.

How We Handle Your Data

Protected at every step — automatically.

You don't have to configure security settings or remember to turn anything on. Protection is the default state of the platform, applied without setup on your part.

Encrypted before it's stored

The database automatically encrypts all data before it's written to disk — no setup or configuration required. It's decrypted transparently only when read by an authorized user, then re-protected.

Keys you never have to manage

Cryptographic keys are managed for you on hardened key-management systems with strict access controls and auditing. Each piece of data is encrypted under the 256-bit Advanced Encryption Standard, and each key is itself encrypted under a regularly rotated set of master keys.

Access stays controlled

Data is decrypted only for authorized users. Because Geckonaut operates the system as a fully managed service, there's no sprawling set of logins to govern on your side — access is limited, deliberate, and reviewable.

A reviewable record

Account activity is captured in audit logs, creating a clear history of actions taken in the system. When HIPAA compliance is enabled, audit logging and multi-factor authentication apply account-wide.

HIPAA & Healthcare

Ready for the standard healthcare demands.

If you run a healthcare practice, compliance isn't optional — and it isn't something to leave to chance. Here's an honest, plain-English look at how HIPAA works with Geckonaut.

What HIPAA actually is

HIPAA — the Health Insurance Portability and Accountability Act — sets U.S. national standards for protecting patient health information. Two parts apply here: the Privacy Rule, which protects patient information, and the Security Rule, which sets standards for securing electronic patient data.

For a healthcare practice, a Business Associate Agreement (BAA) is the contract that formally extends those obligations to the vendors who handle patient data on the practice's behalf.

How Geckonaut supports it

The infrastructure Geckonaut builds on offers an optional, account-wide HIPAA compliance package. When enabled, it brings the controls a healthcare practice needs:

  • Encryption of electronic protected health information
  • Business Associate Agreement coverage
  • Audit logging across the account
  • Multi-factor authentication enforced account-wide

Compliance is a shared responsibility — and we'll be straight with you about it

Under HIPAA, your practice is the "covered entity" and the vendors who handle patient data are "business associates." Full protection of patient data depends on the right agreements being in place across that chain — and on your practice's own internal compliance practices. We don't believe in overstating where things stand. If you're a healthcare practice, we'll walk through your specific HIPAA requirements together during onboarding, make sure the right compliance package and agreements are in place before any patient data is involved, and point you toward qualified compliance consultants where it makes sense. Honest, careful, and done properly — not rushed.

Voice & Call Data

Your calls are data too — treated like it.

An AI voice receptionist creates recordings and transcripts. That's sensitive information, and it deserves the same protection as anything else in your account.

CometConcierge's call recordings, transcripts, and the contact details captured on a call are stored within the same encrypted, access-controlled environment as the rest of your data — not in some separate, less-protected place.

Recordings & transcripts encrypted Voice recordings and their transcripts are encrypted at rest alongside the rest of your account data.
Covered when HIPAA is enabled When the HIPAA package is active, voice recordings are among the data types its safeguards apply to.
Built into the system we manage Because we run the platform for you, call-data protection is configured correctly from day one — not left as a setting you might miss.
Security Questions

The things buyers actually ask.

The infrastructure Geckonaut is built on offers an optional, account-wide HIPAA compliance package. It isn't active by default on any account — HIPAA is something that gets deliberately enabled when a healthcare client needs it.

If you run a healthcare practice, the right approach is a conversation: we'll review your specific requirements during onboarding and make sure the appropriate HIPAA package and agreements are in place before any patient data is handled. We'd rather set this up properly with you than make a blanket claim.

A Business Associate Agreement is a contract that formally extends HIPAA obligations to a vendor handling patient data on a healthcare practice's behalf. If you're a covered entity — a healthcare practice — and a vendor will touch patient information, a BAA is part of doing that properly.

A BAA is included as part of the HIPAA compliance package on the platform. We'll handle getting the right agreements in place as part of onboarding a healthcare client.

Data is encrypted at rest under the 256-bit Advanced Encryption Standard — automatically, before it's written to disk, with no setup needed on your part. It's decrypted transparently only when an authorized user reads it. Data moving between systems is protected with TLS encryption.

Encryption keys are managed for you on hardened key-management systems, and each key is itself encrypted under a regularly rotated set of master keys.

Yes. Recordings, transcripts, and contact details from calls are stored in the same encrypted, access-controlled environment as the rest of your account data. When the HIPAA compliance package is enabled, voice recordings are among the data types its safeguards cover.

No. Geckonaut is a fully managed service. We build, deploy, and operate the system for you — which means security settings are configured correctly from the start rather than left as something you have to find and switch on. You don't log into a dashboard or maintain the platform.

It's shared. Under HIPAA, a healthcare practice is the "covered entity" and the vendors handling patient data are "business associates." Protecting patient data fully depends on the right agreements being in place across that chain — and on your practice's own internal compliance practices.

We'll be transparent about exactly what the platform covers and what stays your responsibility, and we'll point you toward qualified compliance consultants when that's the right move. No overpromising.

Have questions about security or compliance?

Let's talk it through. Book a call and we'll walk you through exactly how Geckonaut protects your data — and what compliance looks like for your specific business.