The agreement

A BAA with every practice.

HIPAA requires a Business Associate Agreement between your practice and any software that touches PHI. Grit includes one with every account — signed during onboarding, automatically, at no extra cost. No paperwork chase, no legal back-and-forth.

Want to read it before you sign up, or have compliance questions? Write us at hello@chiropracticgrit.com — a real person answers.

The controls, specifically.

Encryption in transit & at rest

TLS 1.3 in transit, AES-256 at rest. Patient records are protected end to end.

AWS infrastructure

US-based data centers on Amazon Web Services, which maintains SOC 2 Type II and ISO 27001 compliance.

An audit log that cannot be rewritten

Every access to patient data is written to a clinical audit log that is append-only down to the database itself — entries cannot be edited or deleted, by anyone.

Role-based access

Providers, staff, and patients each see exactly what their role allows. Nothing more.

Two-factor sign-in

Email one-time codes on login keep a stolen password from becoming a breach.

Regular backups

Automatic backups on a regular schedule, so restoration after any incident is fast.

Your data is yours. Always.

If you ever leave Grit, you take everything with you. We don't hold data hostage, and we never sell it — to anyone, for any reason.

  • Full data export — patients, notes, appointments, everything — available anytime
  • Patient data is never sold, shared, or monetized
  • US-based data centers only
  • Data deleted on request when an account closes
Early access

Compliance shouldn't be the hard part.

Join the waitlist and we'll reach out before launch. Compliance questions first? hello@chiropracticgrit.com.

No credit card required.