// security

Built to protect
the clinical relationship.

Every architectural decision — from video infrastructure to payment processing — is designed to keep provider and client data private, compliant, and yours.

We never see your video

Sessions are peer-to-peer via WebRTC. Video never touches our servers.

We never store payment data

All payments handled by Stripe. We never see card numbers or banking details.

Your data stays yours

No selling, no sharing, no third-party ad tracking. Ever.

Consent before every session

Digital consent captured and timestamped before video opens.

Jurisdiction verified

Client location verified against your licensed states before every session.

HIPAA-ready architecture

Built for covered entities. BAA available on request.

// how a session works

Provider
Browser — Safari / Chrome
RS256 JWT←────────→
Client
Browser — Safari / Chrome
⚡ WebRTC peer-to-peer — video never touches InstaRoom servers
api.instaroom.link
Appointments · Auth · Payments
TLS 1.2+←────────→
svc.instaroom.link
MediaDance · WebRTC Signaling
Neon Postgres
Encrypted · us-east-2
+
Stripe Connect
Payments · No card data stored

// technical details

Security questions or to request a penetration test report — hello@instaroom.link