Security

Effective Date: January 1, 2026

Last Updated: August 24, 2026

Recovery is personal. Protecting it is our job.

People trust Ebby with some of the most sensitive information there is. We built RecoveryAI's security program around that fact — not as a compliance checkbox, but because privacy is a condition of recovery itself. This page describes how we protect your data.

Last updated: 8/24/26. Questions: privacy@wearerecoveryai.com.

Encryption

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Journal entries are additionally encrypted with keys held in your device's secure storage, so our servers never store your journal in readable form.

Infrastructure

Ebby runs on HIPAA-eligible cloud infrastructure operated under executed Business Associate Agreements. Production systems are logically separated from development, and access to production is limited to the small number of people who operate it.

Access control

Access to systems that handle user data is role-based and granted on a least-privilege basis. Multi-factor authentication is required for all administrative access. Access is reviewed on a recurring schedule and revoked immediately when no longer needed.

Secure development

Code changes are reviewed before release, and production and development environments are separated. We engage independent security firms to test our defenses: our most recent third-party penetration test was completed with no critical findings, and all findings have been remediated.

Monitoring and incident response

We log and monitor production systems and maintain a documented incident response plan with defined severity levels, escalation paths, and notification commitments. If an incident ever affects your data, we will notify affected users and partners in accordance with our legal and contractual obligations.

Your data is not a product

We do not sell user data. We do not share it with advertisers. User data is never used to train external or third-party AI models.

Compliance

  • SOC 2 Type II. We have engaged an independent auditor (Johanson Group) to conduct a SOC 2 Type II examination of our security controls. Our observation period begins in fall 2026, with the attestation report to follow.

  • HIPAA. Our information security and privacy program is aligned to HIPAA, and where we work with healthcare organizations we operate as a business associate under written Business Associate Agreements. HIPAA readiness is substantially complete.

  • Research ethics. Our clinical research is conducted with academic and clinical partners under applicable ethical oversight.

  • View our Trust Center on Vanta.

Reporting a vulnerability

If you believe you've found a security vulnerability in our products, contact us at privacy@wearerecoveryai.com. We commit to acknowledging good-faith reports promptly and will not pursue action against researchers who report responsibly.

© 2026 Recovery AI, Inc. All rights reserved.

© 2026 Recovery AI, Inc. All rights reserved.

© 2026 Recovery AI, Inc. All rights reserved.