AcuityAI Security:AI that meets your MedTech security standards

AcuityAI secures your sensitive commercial data through enterprise-grade controls and industry-leading privacy practices.

SOC 2 Type II Certified and NIST AI RMF Aligned

SOC 2 Type II Certified
Encryption everywhere
Customer data isolation
Role-based access
Annual independent audit
SOC 2 Type II Certified
No model training
Permission-aware AI
No autonomous actions
Tested before every launch

AcuityAI is SOC 2 Type II certified, which means an independent auditor tested our controls over a multi-month period and confirmed they operated as designed. It's also aligned to the NIST AI Risk Management Framework, which means every AI feature is documented before it ships, tested before deployment, and monitored while it runs.

Protect your data: Enterprise-grade data protection

AcuityAI protects your business data with layered security controls designed to keep information isolated, encrypted, and under your ownership.

Data isolation

Your data is logically isolated and access-controlled within AcuityMD's multi-tenant architecture, with no cross-customer access at any layer.

Encryption by default

Data is encrypted both in transit using TLS 1.2+ and at rest using AES-256 encryption.

You retain ownership

You retain full ownership of your data. AcuityAI acts as a processor, and data can be deleted in accordance with your agreement.

Maintain privacy: Privacy guardrails to protect your data

AcuityAI is designed so you can take advantage of leading AI models without exposing your proprietary data or using it to train third-party models.

No model training

Your inputs are never used to train third-party AI models, and AI vendors cannot train on your data.

Only what's needed

Each request sends the model only what it needs for that task. The model keeps nothing after it responds.

Your activity stays private

Your searches and AI activity are never exposed to other customers. Every third party that processes data on our behalf is security-assessed before onboarding and reviewed on a schedule.

Control access and governance: Security controls that follow your business

AcuityAI carries AcuityMD's existing permissions and security controls into every AI interaction, so users only see and act on the data they're authorized to access.

Permissions carry into AI

Role-based access controls govern data access, and AcuityAI responses respect the same permission boundaries already established in AcuityMD.

No unauthorized access

Your data stays limited to the people authorized to see it. AcuityAI respects your existing permissions and access controls, with least-privilege principles enforced throughout the platform.

You stay in control of AcuityAI actions

AcuityAI can surface recommendations and next steps, but it never acts on your behalf. You decide what to act on, and every action remains under your control.

Role permissions: Users only see the territory, region, and quotas relevant to them

Manager access

Their reps' territories

Rep access

Their territory only

No access

Territories outside their scope

Security FAQs

Expand all

Which AI models does AcuityAI use, and where does our data go?

AcuityAI is vendor-agnostic, so we adopt best-in-class models rather than locking to one provider. Whichever model runs a request, that vendor is contractually prohibited from training on your inputs and is configured for zero data retention where available. Only the data a task requires is sent to the model.

Who can see our data or our AI activity?

Access to customer data is governed by role-based access control under least-privilege principles, with centralized logging, monitoring, and audit trails. Your search and AI activity is never exposed to other customers, and no third party receives raw or identifiable data.

Where does AcuityAI get its information?

AcuityAI works from three sources: AcuityMD's proprietary MedTech dataset, public web sources, and the context your team adds inside the platform. It does not pull from other customers' data, and it has no access to anything outside what your own permissions allow.

How long do you keep our AI activity, and can we delete it?

You retain full ownership of your data, and AcuityAI acts as a processor rather than an owner. Data is retained according to your contractual agreement, and you can request deletion at any time. Deletion follows a documented process that removes data from active systems and propagates through backups on our retention schedule.

Does AcuityAI process patient data?

No. AcuityMD's core dataset covers provider and facility-level activity, not individually identifiable patient information, so AcuityAI does not process PHI in the standard product.