Talk Doc
Talk Doc

We limit who can reach your information, and what can reach it. The protection changes with the job.

Clear boundaries for sensitive work

TalkDoc limits who, and what, can enter each workflow. The protection changes with the job. Technology does not change who is responsible for your care. No online service can promise perfect security.

We do not sell your data for ads

TalkDoc does not sell personal information, and does not share it for cross-context behavioral advertising. We do not disclose health information to third-party advertisers for targeted ads.


Access should match the job

People and systems get access only when their work requires it. Care, billing, support, and AI use different workflows with different controls.


Not every part is sealed

Eligible private patient AI and certain in-visit paths are designed to run inside confidential-computing boundaries. Scheduling, the community site, phone workflows, billing, and some clinician tools use separate systems under their own protections, including HIPAA Business Associate Agreements where they apply.


The sealed part, in more detail

IronEgg is our name for the confidential-computing architecture behind eligible AI workflows. What follows applies only where that architecture is enabled. It does not apply to every part of the product.

IronEgg is being rolled out in stages. The deployed scope varies by feature and by technical environment.

Hardware isolation

Eligible workloads are designed to use confidential-computing hardware that isolates protected memory from the surrounding host and from ordinary operators.

Attestation evidence

The architecture can produce evidence about the software image running inside an eligible environment. Direct client verification and broader assurance remain staged.

Encrypted envelopes and short-lived keys

Eligible requests and responses are designed to cross the enclave boundary as ciphertext. Identity keys are meant for a running environment, and are destroyed at shutdown.

Scope note. GPU attestation, direct client verification, OHTTP routing, and independent assurance remain staged work. AI does not independently diagnose, prescribe, or replace a licensed clinician.

A woman looking at her phone

Security is shared

Use a unique password and keep your sign-in information private. Sign out on shared devices, and keep your device software current.

Read our privacy policy ➝

Only what we can stand behind

HIPAA-aware operations

Clinical services are delivered by licensed providers. TalkDoc supports those relationships with contracts and safeguards appropriate to each role, including Business Associate terms where HIPAA applies.

What we do not claim here

This page is not a SOC 2 report, a penetration-test certificate, or a third-party audit badge. When independent assurance is published for a specific scope, we will say so clearly.

Where to read more

Our AI page says more about where AI is used and what it does not do. Our Privacy Policy and our Terms cover the rest.

Tell us when something looks wrong

If you believe your TalkDoc account or information may be at risk, email support@talkdoc.com. Please tell us promptly about unfamiliar activity or a suspicious message. Do not email medical details or passwords.