CitigenVoice

Security and data handling

A factual overview of the controls currently built into Citigen Voice.

Tenant isolation

Office data is scoped to an authenticated organization membership. Provider routes, administrative tools, background work, and customer portal queries resolve the office on the server rather than trusting a browser-supplied workspace identifier.

Access controls

Office access is invitation-based and uses owner, administrator, and member roles. Platform operations access is separate from office membership, requires a dedicated platform role, and can require multi-factor authentication for privileged workflows.

Provider and payment security

Provider callbacks are authenticated, rate limited, and designed for safe retries. Stripe manages payment-card collection; Citigen Voice does not store complete payment-card details.

Recording and transcript controls

Call recording is disabled by default. Offices control whether eligible transcripts are stored and select a retention period. Access to transcripts is restricted to authorized members of the relevant office.

Operational privacy

Platform-wide operational views avoid caller identity, transcript content, authorization values, and clinical details. Privileged administrative changes are restricted and recorded for audit.

Healthcare deployments

Citigen Voice is an administrative service, not a healthcare provider. Each workspace must complete its own privacy, consent, vendor, and Business Associate Agreement review before using the service with protected health information. This page does not claim that every deployment is HIPAA compliant.

Report a concern

Send security or privacy questions to privacy@citigenvoice.com. Do not include customer information, credentials, secrets, or production payloads in email.