Security, plainly.

The one-breath answer: we reach one dedicated workstation through Splashtop, the same remote-access tool IT providers use. The session is encrypted end to end, nothing is opened on your firewall, we cannot see the rest of your network, and you can remove us any time by uninstalling the app. The longer answers are below, for your IT and compliance people.

Remote access

How do you reach our systems?

Through one dedicated workstation, with Splashtop Business: the same category of remote-access software IT providers and clinics already use. A small app runs on that workstation; we connect from our own computer with our own named login and two-factor. Nothing for your team to install beyond that app.

Do we need to open ports or change our firewall?

No. The app only makes outbound connections, like a browser.

Can you see our network?

No. We can reach that one workstation, nothing else. There is no network tunnel into your office.

Who can log in, and how?

Named people only, with two-factor on our account. Every session is logged on our side: who, which computer, when.

Is it logged?

Yes. Splashtop logs every session. The agent keeps its own action log on the workstation, and it works under its own login in your software, so every action it takes is attributable to it and only to it.

Can Splashtop, the company, see our data?

No. The screen stream and keystrokes are encrypted end to end; Splashtop transmits them but does not store them. In their own words, Splashtop “does not process, store, or have access to any of the users’ computer data such as patient data or medical records.”

Do you have a BAA with Splashtop?

Splashtop states it never accesses the data, which is the same position your internet provider is in. Our business associate agreements are with the parties that do touch data: with you, and with AWS for the document-reading step.

Our IT wants to review it.

Good. We send a one-page install note, this page, and Splashtop’s own security documentation. Your IT can inspect the app and remove it whenever they like.

Where data goes

Where does the work happen?

The agent runs on your own workstation, inside your software. One step leaves it: reading a document, which runs on AWS Bedrock under a business associate agreement. Bedrock does not store the content or use it to train models. Run logs stay on your workstation, in your own systems.

What exactly leaves the workstation?

Only what the one decision needs: the document being read and the question about it. Not the chart. Not the history. The call is logged (who, when), not the content.

What runs on the workstation?

The remote-access app, a browser, and our agent, under its own local user. Passwords live in the operating system’s protected store (Windows DPAPI or macOS Keychain), never in a file, an email or a chat message.

Does the agent depend on someone watching?

No. It keeps running whether or not anyone is connected, and reports status and counts to our side over ordinary HTTPS. Status and counts only.

And this website?

The Site runs no advertising trackers, no analytics scripts, and no social-media pixels. We collect information only when you give it to us: the discovery form, the booking calendar, or an email. The Privacy Policy has the rest.

What we never do

Guess.

Every action is read back from the screen before it counts. A click we can’t confirm is a click that didn’t happen. When it can’t prove something, it stops and asks a person.

Improvise around your rules.

The rulebook is yours, written in plain sentences. Sumvant follows it. It does not improvise around it. Only your team changes a rule.

Run alone before it has earned it.

It works real items while we watch and your team reviews the results. Every action read back; every exception explained. Nothing runs alone until it has earned it.

Open your network.

We reach one workstation, with a named login and two-factor, and every session is logged. No ports opened, no tunnel into your office.

Keep your data somewhere else.

Run logs stay on your workstation, in your own systems. The one document-reading step runs under a business associate agreement and is not stored.

Call ourselves certified.

There is no such thing as a HIPAA certification, and we do not claim one for ourselves or for our tools. We sign business associate agreements where health information is involved, and we hold one with AWS for the document-reading step.

How to remove us

How do we shut it off?

Uninstall the remote-access app, or disable the agent’s login in your software. Either stops us immediately. We also give you a one-page offboarding note before go-live.

What happens to the work and its records?

Work we do for clients is governed by the written services agreement, and where health information is involved, a Business Associate Agreement, signed with each client. The run logs were on your workstation all along; they stay with you.

And what you hold from this site?

You can ask us at any time to tell you what information we hold about you, correct it, or delete it. Email [email protected] and we will respond within 30 days.

Ask the hard questions first.

Send this page to whoever has to sign off. If something is missing, write to [email protected] and a person will answer.