In short
Consig is built to carry protected health information. It operates in compliance with HIPAA and signs a Business Associate Agreement with healthcare customers before any PHI is shared. Patient identity is verified through a Zero Knowledge Network, so credentials and biometrics never enter the AI, the LLM, or the transcript. A compliance engine applies federal and state calling rules to every call.
- HIPAA
BAA before any PHI
Healthcare customers sign a Business Associate Agreement with Consig before sharing protected health information.
- Identity
Zero Knowledge verification
Passkeys, device biometrics and one-time passcodes. The identity data never reaches the AI or the transcript.
- AI
Governed conversations
Calls mix scripted, deterministic steps with generative AI used only where approved, behind context firewalls.
- TCPA
Rules enforced per call
The compliance engine tracks federal and state rules and flags risky steps while you build a workflow.
- PCI DSS
Level 2
Payment card data is handled in compliance with PCI DSS at Level 2.
- Privacy
We do not sell data
Consig does not sell personal information. Customers can request deletion of recordings and transcripts.
How does Consig handle protected health information?
Consig operates in compliance with the Health Insurance Portability and Accountability Act (HIPAA). Healthcare customers must have a signed Business Associate Agreement with Consig before sharing any PHI, the agreement that makes Consig contractually and legally accountable for safeguarding it.
Inside a call, sensitive information is only disclosed after the patient is verified. In configured workflows, identity verification happens before PHI is discussed, and it leaves an audit trail.
How is patient identity protected on a call?
Consig authenticates patients at the start of the call with passkeys, device-native biometrics such as Face ID or Touch ID, one-time passcodes, and step-up verification for higher-risk moments such as prescription confirmations, billing, or post-discharge instructions.
The identity layer is Journey.ai's patented Zero Knowledge Network®, embedded in every Consig call through an OEM partnership. It returns the authentication result the workflow needs while the credentials themselves stay out of Consig's conversation layer, out of call transcripts, and out of any third-party LLM in the call path.
How is the AI on a call kept in bounds?
Consig workflows combine deterministic, scripted stages with generative stages, and generative AI runs only where it has been approved. The steps that must be exact (disclosures, consent capture, opt-outs, identity checks) can run as scripted flows rather than being left to a language model.
Consig also runs conversational context firewalls that keep sensitive data out of the model's reach. The same foundation lets a call capture consent, collect health data, or take in a form without that data passing through the AI. See What AI should (and should never) do on a patient call.
How does Consig keep calls within TCPA and state rules?
A single automated patient call can fall under telecom, healthcare, and AI law at once, and the rules change by state. Consig's compliance engine tracks the relevant federal, state, and local policies, applies the calling rules that govern each call, and flags risky steps in the portal while a workflow is being built.
The research behind this is summarized in One Call, Three Rulebooks, with more on TCPA, consent revocation, and AI voice disclosure laws in the glossary.
How is customer data handled?
Consig does not sell personal information. Call data is shared only with the customer who owns the patient relationship, with service providers that meet equivalent privacy and security standards (such as cloud hosting, transcription, and analytics providers), and with authorities when the law requires it. The Consig platform runs on Amazon Web Services.
Customers can ask for recordings, transcripts, and related data to be deleted. Data use and retention are set out in the Privacy Policy and in each customer's agreement. Payment card data is handled in compliance with PCI DSS Level 2.
What are customers responsible for?
Compliance is shared. Consig enforces calling rules in the platform, and customers stay responsible for the consent behind each call. Under the Acceptable Use Policy, customers must obtain every consent the TCPA and related laws require before calls are placed, keep records of those consents, and provide them on request.
Report a security issue
Email privacy@consig.ai with a description and steps to reproduce. Please give us a reasonable chance to investigate before disclosing anything publicly. Machine-readable contact details are at /.well-known/security.txt.
Frequently asked questions
Is Consig HIPAA compliant?
Yes. Consig operates in compliance with HIPAA and is built to process protected health information on outbound patient calls. Healthcare customers sign a Business Associate Agreement with Consig before any PHI is shared, and in configured workflows patients are verified before sensitive information is disclosed.
Will Consig sign a Business Associate Agreement?
Yes. A signed BAA is required before a healthcare customer shares PHI with Consig, so it is part of every healthcare engagement rather than an optional add-on. Talk to a Solutions Architect to start the process.
Does patient identity data reach the AI model?
No. Consig verifies identity through Journey.ai's Zero Knowledge Network, which returns only the authentication result. Passkeys, biometrics and one-time passcodes never enter the voice AI or LLM environment and never appear in a call transcript.
Where does Consig run?
The Consig platform runs on Amazon Web Services. Cloud hosting, transcription and analytics providers that handle customer data must meet privacy and security standards equivalent to Consig's own, as described in the Privacy Policy.
Does Consig handle payment card data?
Consig complies with the Payment Card Industry Data Security Standard (PCI DSS) at Level 2 and plans to obtain Level 1 certification.
Who is responsible for TCPA consent?
Both parties. Consig's compliance engine enforces calling rules on every call, and the customer is responsible for obtaining and documenting the consents the TCPA and related laws require before calls are placed, as set out in the Acceptable Use Policy.
How do I report a security issue or ask a security question?
Email privacy@consig.ai. Include enough detail to reproduce a suspected vulnerability. Security questions from a vendor review can go to the same address or to your Consig contact.