Data stays in the U.S.
Client records are hosted on U.S. infrastructure and never leave the country as part of normal operation.
Counseling records are among the most sensitive data a person will ever share. Nimbli treats them that way — U.S. hosting, encryption everywhere, least-privilege access, and AI that never acts without a clinician's approval.
Client records are hosted on U.S. infrastructure and never leave the country as part of normal operation.
TLS on every connection and strong encryption at rest. Telehealth sessions are encrypted end to end.
Role-based permissions, per-practice isolation in our multi-tenant architecture, and full audit trails.
Nimbli is built to U.S. privacy expectations for health information, and we support your practice's own obligations to its clients and regulators.
AI Scribe never writes to a chart on its own. Every note is a draft until a clinician reads, edits, and approves it. Client data is not used to train third-party models.
Security is a practice, not a badge. Here's how we keep it steady.
Encrypted, automated, and regularly tested for restore.
Continuous monitoring and alerting across the platform.
Regular reviews of who can reach what, and why.
A defined plan and clear client notification commitments.
We're glad to walk your team, your privacy officer, or your regulator through how Nimbli protects clinical data.