Encryption in transit & at rest
TLS 1.3 in transit, AES-256 at rest. Patient records are protected end to end.
A chiropractic practice handles protected health information all day, every day. Grit was built with the controls, the infrastructure, and the agreements that responsibility requires — from the first line of code, not as a retrofit.
HIPAA requires a Business Associate Agreement between your practice and any software that touches PHI. Grit includes one with every account — signed during onboarding, automatically, at no extra cost. No paperwork chase, no legal back-and-forth.
Want to read it before you sign up, or have compliance questions? Write us at hello@chiropracticgrit.com — a real person answers.
TLS 1.3 in transit, AES-256 at rest. Patient records are protected end to end.
US-based data centers on Amazon Web Services, which maintains SOC 2 Type II and ISO 27001 compliance.
Every access to patient data is written to a clinical audit log that is append-only down to the database itself — entries cannot be edited or deleted, by anyone.
Providers, staff, and patients each see exactly what their role allows. Nothing more.
Email one-time codes on login keep a stolen password from becoming a breach.
Automatic backups on a regular schedule, so restoration after any incident is fast.
If you ever leave Grit, you take everything with you. We don't hold data hostage, and we never sell it — to anyone, for any reason.
Join the waitlist and we'll reach out before launch. Compliance questions first? hello@chiropracticgrit.com.
No credit card required.