Security & compliance
Built with a healthcare-aware posture from day one.
We're early — we'd rather tell you exactly where things stand today than lean on badges that don't mean much on their own.
Every practice is isolated by design
Every patient, session, note, and form is scoped to your organization at the database level, and every action re-checks your membership independently — not just at the page, but on every read and write. An unguessable, time-ordered id is never treated as a substitute for that check.
Significant actions record who, not just when
Where it matters — overlap overrides, cancellations, guest reviews — we record who made the change alongside the timestamp, so there's always an answer to "why does this look the way it does," not just "when did it happen."
Deletes are recoverable, not silent
Nothing is purged automatically. Deleted records move to Trash and can be restored, rather than disappearing the moment someone clicks the wrong button.
Authentication is self-hosted, not outsourced identity
Sign-in and organization membership run on Better Auth, under our control, rather than trusting a third party with the keys to every practice's data.
Where we are, and where we're headed
Today, non-production environments run on synthetic or de-identified data, and any vendor that would touch real patient information is held to the same bar: a signed Business Associate Agreement covering the exact product and use, not just a general "SOC 2" or "encrypted" claim. Before any practice puts live patient data through Goji in production, we're confirming that bar end to end — BAAs, encryption, backups, retention, audit logs, and support access — with our planned infrastructure (AWS for storage, email, and durable notification delivery under one HIPAA-covered boundary).
If you're evaluating Goji for a real practice and want the specifics of where that stands, ask us directly — we'd rather have that conversation than have you guess from a badge.