Psynth gets clean SOC 2 Type II attestation for psychological assessment AI
Psynth said it completed a SOC 2 Type II audit with an unmodified opinion and no exceptions, adding to its HIPAA, GDPR and PIPEDA compliance program. The company also made its security evidence publicly available as it expands AI tools for psychologists across the U.S. and Canada.
Why it matters: - Psychological assessment workflows often involve highly sensitive patient records, session data and reports. - Psynth is using the attestation to signal that clinicians can review independent security evidence instead of relying on sales claims. - The company’s public trust center gives customers access to audit reports, policies, subprocessors and control evidence at trust.psynth.ai.
What happened: - Psynth said Wednesday it completed a SOC 2 Type II examination and received an unmodified, or clean, opinion from an independent audit firm. - The review covered the design and operating effectiveness of controls against the AICPA Trust Services Criteria for Security over a three-month period. - The audit found no exceptions. - The company is based in Tulsa, Oklahoma.
The details: - Psynth operates as a HIPAA Business Associate to clinician customers and as a data processor under GDPR and PIPEDA. - The company’s assessment pipeline includes ambient session listening, data extraction and report generation. - Those workloads run inside Psynth’s audited cloud infrastructure. - Patient records, session data and finalized reports are stored at rest in the customer’s designated region: the United States, the European Union or Canada. - For Canadian customers, Psynth says data at rest stays in Canadian data centers and processing uses Canadian-region services where available. - If a required capability is not offered in-region, processing moves to a Psynth-controlled environment under contractual safeguards consistent with PIPEDA, and the resulting data is stored at rest in Canada. - Psynth said ambient listening and AI-assisted report generation are already in market for clinical, neuropsychological and forensic psychologists in the U.S. and Canada. - Intake capabilities are scheduled to follow. - The company says clinicians keep all clinical judgment, while Psynth drafts and the provider reviews, edits and finalizes.
Between the lines: - Psynth is positioning security and data residency as product features, not just compliance checkboxes. - The company is also drawing a contrast with AI platforms that rely on third-party infrastructure settings the customer cannot easily inspect. - CEO Stephen Stearman said the company has not found another psychological assessment platform publishing this combination of attestations. - Stearman also said Psynth intends to keep what it calls the most transparent security posture in the category.
What's next: - Psynth plans to add intake capabilities after the current products already in market. - The company said it will continue publishing security evidence openly rather than hiding it behind a sales process. - Psynth is also maintaining its trust center and compliance materials for customer review as adoption grows.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Canadian Environmental News Wire
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.