Trust Center· Last updated 12 May 2026

How we earn the
exam-room trust.

One page. Every commitment, every control, and every practice we will never break. Published next to its current status so you can see what is live, what is being built, and what we will never do.

Contact security
Current posture
Live
Encryption everywhere
US
Data residency
72h
Incident SLA
Never
Sold for ads
HIPAA-comparable by choice

On this page

Commitments

What we promise.

Seven commitments. Plain English. Binding.

Highest standards.

OpenVet protects your data with the security and privacy controls used by serious clinical platforms.

Confidential by default.

OpenVet collects information needed to do its job. That information stays confidential.

Used to serve you.

Your information is used to answer clinical questions, improve accuracy, build population-level intelligence, and support your practice.

Never sold.

OpenVet will never sell your data.

You are the user, not the product.

OpenVet's incentives are aligned with vets. Not with advertisers, not with data brokers, not with PIMS resellers.

Free to encourage use.

OpenVet is free for vets so it gets used widely, learns faster, and keeps improving for everyone.

AI-specific security.

OpenVet applies safety controls built for clinical AI. Not generic web security retrofitted to a chatbot.

02 · Never
Never. Not under any circumstances.

What we will never do.

  • Sell data that identifies you or your clients.
  • Share your personal information with anyone outside the providers needed to run the service.
  • Share your standalone clinical queries with your employer or practice admin.
  • Sell data that identifies you or your clients to advertisers, data brokers, or PIMS vendors.
  • Use your queries to train third-party AI providers' general-purpose models.
  • Change these practices without notifying you first.
03 · Safety Charter

Four principles that govern every release.

Written down so every internal decision can be measured against them, and so a vet, a regulator, or a researcher can hold us to them in public.

§ 01

Deterministic where it must be

Drug doses are validated against verified formulary. They are never AI-generated. Species-specific safety checks run before any output. Where uncertainty exists, the system surfaces it. It does not paper over it.

§ 02

Reviewed by clinicians

Every clinical room is reviewed by qualified veterinarians before launch, including board-certified specialists where the room's content warrants it. Every protocol is audited and versioned. The clinical review group grows with the product.

§ 03

Auditable always

Every answer carries its citation, its source tier, and its stated assumptions. The vet sees exactly why the system said what it said, and can trace every recommendation to its source.

§ 04

The vet remains responsible

OpenVet supports clinical judgment. It does not replace it. The final call belongs to the clinician. Explicitly, and by design.

§ 05

Input and output safety

Inputs are screened for prompt injection and adversarial content. Outputs are filtered for unsafe recommendations before reaching the vet. Suspicious cases are routed to safer handling paths.

04 · Privacy

Your data, in plain English.

Mirrors the binding Privacy Policy. Where they differ, the Policy governs.

Private by default

Standalone clinical queries are visible only to you. Attaching a query to a patient record makes it part of that record, visible to your practice team. That is the only action that changes visibility.

US data residency

OpenVet operates on US-based infrastructure. Your data does not leave the country in the ordinary course of operations.

No third-party training

Our AI model providers do not use API inputs or outputs to train their general-purpose models by default, subject to provider terms and our configuration.

No sale of identifying data

We do not sell, rent, or share personal information with advertisers, data brokers, or third parties for their independent marketing. Applies under all US state privacy laws.

Delete your account

Email privacy@openvet.ai or use the in-product control. We complete verified deletion within the timeframe set in our Privacy Policy, except where law requires retention.

Notice of material changes

New categories of data collection or new categories of recipients trigger advance notice by email and in-product, with an opportunity to opt out.

What we collect
Account informationName, email, role, license number, jurisdiction
Clinical queriesQuestions you submit and responses returned
Case contentPatient and client information you add to a case
Ambient audioAudio recordings retained per the Privacy Policy. Transcripts retained as part of the case record.
Usage dataFeatures used, session duration, page navigation
Device dataIP, browser, OS, device identifiers, crash logs
Payment dataProcessed by Stripe, where applicable. We do not store cards.
Who can see what
Standalone query
You and OpenVet
Query attached to a patient
You, your practice team, and OpenVet
Aggregate de-identified usage
OpenVet and partners. No identifiers.
Enterprise admin analytics
Practice admins see totals, not queries.
05 · Compliance status

What is live today.

Every row has an internal owner who confirmed it within the last seven days.

LIVEEncryption
Encryption in transit (TLS 1.3)
-
LIVEEncryption
Encryption at rest (AES-256)
-
LIVEVendors
Sub-processor SOC 2 Type II coverage
-
LIVEAccess
MFA support
-
LIVEPosture
HIPAA-comparable controls by choice
-
LIVEIncident
72-hour breach notification commitment
-
LIVEPosture
Responsible disclosure program
-
LIVE (ON REQUEST)Enterprise
Enterprise Data Processing Agreement
-
IN PROGRESSData Layer
Row-level security on clinical tables
Target: Q3 2026
LIVESurface
Marketing site security headers (HSTS, CSP)
-
IN PROGRESSAccess
Automated state-board license verification
Target: Q3 2026

Live on this table is a public commitment. In Progress carries a near-term target. Longer-horizon items are tracked internally and shared with enterprise procurement on request.

06 · Security controls

Ten controls. Grouped by what they protect.

Live today. Where uncertainty exists, the compliance status section names it.

Encryption2 controls
§ 01

Encryption in transit

TLS 1.3 across all OpenVet application endpoints. HSTS enforced. No legacy TLS versions accepted.

§ 02

Encryption at rest

AES-256 encryption on the primary database. Object storage encrypted at the provider layer (Supabase). Keys managed by the infrastructure provider.

Access & Identity3 controls
§ 03

Authentication

Clerk-managed authentication. Multi-factor authentication is supported for all accounts. Passwords are never stored in plain text. Session tokens are short-lived and rotate.

§ 04

Access controls

Production data access is restricted to essential OpenVet personnel. Internal access requires MFA, follows least-privilege principles, and is logged.

§ 05

License verification

Every DVM account is tied to a license number captured at sign-up. Reviewed by the OpenVet team. Automated state-board verification is in development.

Data Layer2 controls
§ 06

Database-layer security

Row-level security policies are deployed on clinical and account tables. Coverage is being extended to all clinical tables; remaining tables are tracked and being closed.

§ 07

Audit logging

Key clinical actions, including queries, case modifications, and access events on protected tables, are recorded with timestamps, user identifiers, and action types.

Surface3 controls
§ 08

Endpoint hardening

HSTS, Content Security Policy, and per-user rate limits are enforced on the OpenVet application. We are extending the same header policy to all OpenVet web properties.

§ 09

US infrastructure

OpenVet's primary application and database operate in US regions. Where any processor operates outside the US, it is disclosed in our Privacy Policy or on request.

§ 10

Payment security

Where payment processing applies, card data is processed by Stripe (PCI-DSS Level 1). OpenVet does not store card numbers.

07 · Incidents & disclosure

When something goes wrong.

A 72-hour notification commitment, and a responsible-disclosure program with non-retaliation in writing.

72hLIVE

Breach notification SLA

If we determine that a security incident has materially affected your personal information, we will notify you within 72 hours of confirmation, by email and where appropriate by in-product notice. The notification describes what happened, what was affected, what we are doing in response, and what steps you can take.

Responsible disclosure

Find something? Tell us.

Email security@openvet.ai with the issue and steps to reproduce. We acknowledge within 48 hours and coordinate disclosure with you.

No legal action against good-faith researchers.
Public acknowledgment with your permission.
Coordinated disclosure timing, typically 90 days.
08 · Environmental

Honest about our footprint.

We are not going to tell you AI has zero environmental impact. Anyone who says that is spinning you. Here is what is actually true about OpenVet. This page is our environmental note: short, plain English, and updated as we learn more.

How we stand apart

Built lean on purpose

OpenVet does not run a brute-force search across everything for every question. It draws on a curated, structured knowledge base, so by design each answer moves fewer words through the AI than a heavy retrieval approach would, the same answer, with less computation and less energy.

By the numbers
~0.24 Wh
Energy per question, about the same as a web search
~0.03 g
CO₂ per question
~0.26 mL
Water per question, roughly five drops
30×+
More efficient per prompt than a year ago (and than basically all the others on the market!)

Figures are the latest published measurements for AI text prompts of this kind, not a number we invented. We update them as better data becomes available.

§ 01

About the size of a web search

By the latest published measurements, a question like the ones OpenVet runs on uses about 0.24 watt-hours of energy, the same order of magnitude as a single web search (~0.3 Wh), and less than ten seconds of watching television. A year ago the same prompt cost more than thirty times as much. This is important to us, and as we've focused on efficiency, we were able to make our technology dramatically more efficient for you, our community, and for the environment.

§ 02

We do not build the engines, we use them

Training an AI model from scratch is the part that consumes enormous energy. OpenVet does not do that. We are a lightweight layer on top of existing models, which keeps our footprint a small fraction of what makes AI headlines.

§ 03

Efficiency is built into how it works

We do not throw maximum horsepower at every question. The system uses the lightest model that returns the right answer, and reuses work it has already done, so each question draws less power than it otherwise would.

§ 04

We measure, and we show our work

We publish the numbers we can measure, and we will not invent ones we cannot. As far as we know, that makes OpenVet the first veterinary AI to publish an environmental note. We keep this page current as the figures move.

Straight answers to the questions we get asked
Carbon footprintAbout 0.03 grams of CO₂ per question. Because we do not train models, the carbon-heavy part of AI, our share is small.
Water useAbout 0.26 mL per question, roughly five drops. The cooling water sits with the shared infrastructure we run on, which reports its own usage.
Emissions reportingWe publish what we can measure and control, and we will not manufacture a number we cannot stand behind. This page is that report, kept current.
Green computeWe pick the smallest model that gets the answer right and reuse work already done, so each question draws less power.
Carbon offsetsWe would rather use less energy than buy offsets to claim 'net zero.' If we ever buy them, we will say exactly what and why.
Data-center impactOpenVet does not operate data centers. We are a light tenant on shared infrastructure that has become more than thirty times more efficient per prompt in a single year.
On the environment, specifically

Where we draw the line.

  • Pretend our environmental impact is zero.
  • Buy cheap carbon offsets so we can slap a green badge on the product.
  • Make environmental claims we cannot back up.
  • Waste compute just to look impressive.
09 · Questions

The ones vets ask most.

Send yours to privacy@openvet.ai and we will add the good ones.

No. HIPAA does not apply to veterinary records. We apply HIPAA-comparable security controls by choice, but we do not sign BAAs.
Still need an answer?

We answer every email about safety or privacy.