Talkie builds and operates AI Agents for healthcare. Our agents handle patient–clinic communication end-to-end—voice calls, web chat, and SMS—so patients get 24/7 access to care and busy practices never miss a conversation.
Our security controls are independently verified—through SOC 2 audits, third-party penetration tests, and GDPR audits. We meet HIPAA and GDPR requirements, as well as EU AI Act regulations.
Review the controls we maintain below, and request supporting documentation any time.
Talkie operates across two regulatory environments—US healthcare and EU data protection—and is audited against both.
Talkie acts as a Business Associate to covered-entity clients and handles PHI accordingly.
Our controls have been examined by an independent CPA in 3 consecutive audits (April 2024, December 2024, July 2026.)
Full report available—request by contacting security@talkie.ai.
Our EU client base means GDPR is a requirement.
Talkie’s voice AI agents comply with the requirements of the EU AI Act.
Talkie’s AI governance follows the four functions of the NIST AI Risk Management Framework.
Every control traces back to a written, maintained policy. Summaries are available on request for enterprise security reviews.
An independent external provider conducts penetration testing annually, on a rolling schedule. Findings are tracked through to remediation and reviewed by executive leadership as part of our quarterly and annual security reviews. Scope was expanded in the most recent cycle to explicitly cover three areas:
Web application and product-layer testing
DMZ and perimeter infrastructure
Full AWS cloud infrastructure audit
“Security measures, especially personal data protection, is of utmost importance at Talkie.ai. It’s important for our clients to be able securely integrate our systems and solutions with their platforms, encrypt data, and back up and store data to standards that meet and ideally exceed the requirements of the healthcare industry.”
Wojciech Przechodzeń
CPO, Talkie.ai
Request our SOC 2 Type II report, BAA template, or pentest attestation letter—most are shared under NDA within 3 business days.
You can reach us by emailing security@talkie.ai or by submitting the form below.
Is Talkie HIPAA compliant?
Yes. Talkie acts as a Business Associate to covered-entity clients and handles PHI accordingly. We execute a Business Associate Agreement (BAA) with every US healthcare client, and with any subprocessor that may process PHI.
Is Talkie SOC 2 audited?
Yes. Our controls have been examined by an independent CPA across three SOC 2 Type II audits, covering all five Trust Services Criteria—Security, Availability, Confidentiality, Processing Integrity, and Privacy. Every report confirmed our controls are suitably designed and operating effectively.
Can I see your SOC 2 report and other documentation?
Yes. Email security@talkie.ai to request the full SOC 2 report, penetration-test summary, and related documentation.
Where is our data stored, and is it encrypted?
Talkie runs on Amazon Web Services, with data residency enforced per market—US client data is processed and stored in US regions, and EU client data stays in EU regions. Confidential and highly-confidential data is encrypted at rest using AES-256, and data in transit is protected with TLS 1.3 across production services.
Are patients told they’re speaking with an AI agent?
Yes. Disclosure that a caller is interacting with an AI agent is built into how our agents operate, in line with EU AI Act transparency requirements.