Safety & compliance

Built to protect the people in the room.

RoundPenVR handles sensitive material, so safety and privacy are architectural, not add-ons. Sessions are always supervised, capture is always consented, and the platform runs to a HIPAA-standard safeguard model on AWS.

In the headset

Client safety, by design

The experience is engineered so a client never gets startled, cornered, or stuck. The coach can end any session in a single tap, and the client always has a way out.

  • Instant exit gesture — both hands raised for three seconds routes straight to the gentle close and alerts the coach
  • No startle stimuli — no sudden sounds or movements; storms and predator imagery are prohibited
  • Never an abrupt end — every session finishes with the mandatory departure sequence
  • Intensity ceiling — the archetype's reactivity is capped per client and can never exceed it
  • Distress indicator — sustained agitation raises a visual flag for the coach; no automated action is ever taken
A shield with a lock representing HIPAA-standard safeguards

No unsupervised sessions — enforced, not promised

There is no solo client mode in any build. If a remote coach loses connection, the session pauses within seconds. A session that ends without a coach's signed attestation is flagged and escalated to the program admin. Supervision isn't a policy you have to trust — it's built into how the software runs.

Consent & privacy

Capture is gated on consent — every time

Consent is granular, versioned, and immutable. If a permission isn't active, the data is never transmitted in the first place.

Granular permissions

Separate flags for voice recording, transcription, remote-coach presence, supervision review, and per-recipient care-team export. Each can be granted or withheld independently.

Consent-aware transmission

Telemetry features are computed on the headset, but only transmitted if the matching consent is active. Camera and passthrough footage is never transmitted or stored — at all.

Immutable versioning

Consent records are versioned and can't be edited after the fact. Past session records keep the exact consent that applied at the time.

Platform safeguards

A HIPAA-standard safeguard model

The platform operates under an AWS Business Associate Agreement, with program-level agreements templated and tracked. A HIPAA applicability determination per program is a deployment prerequisite.

ControlHow it's implemented
AccessMFA for coaches and admins, role-based access, per-tenant encryption keys, and break-glass access that requires written justification and alerts the compliance owner.
AuditEvery access to sensitive data is logged with actor, resource, and time, written to an immutable trail with a scheduled review procedure.
IntegrityVersioned, write-once storage with object lock; envelope encryption; and a checksum embedded in every export bundle.
TransmissionTLS everywhere, private network paths for compute, and short-lived signed links for any playback or download.
Encryption at restPer-tenant customer-managed keys, encrypted databases, and encrypted backups.
Session controlConsole idle logout, a hard session-duration cap, and no persistent storage on the headset.
ContingencyA documented backup and restore runbook with an annual restore test and cross-account snapshot copies.
Incident responseAutomated alarms to an on-call channel and a breach-notification runbook keyed to the data class involved.
Data minimization

What we deliberately don't collect

The safest data is the data that never exists. Several limits are enforced by the schema itself.

No clinical records

There are no diagnosis, treatment-plan, or assessment structures anywhere in the data model. By design, they cannot be stored — only session records, observations, and coach annotations.

No footage

Headset camera and passthrough imagery is never captured or transmitted. Raw audio is stored only when voice-recording consent is active; otherwise only extracted features leave the device.

No training on your data

Session data is never used for model training, fine-tuning, or analytics beyond de-identified aggregate counts. Any optional AI assist produces behavior parameters only — never text or interpretation.

Tenant isolation

Every program's data is isolated, with a tenant check enforced at the API layer on every request. Cross-tenant access is denied before it reaches your data.

A note on scope. RoundPenVR is a supervised practice environment, not therapy and not a medical device. It supports equine-assisted coaching programs; it does not diagnose, treat, or replace professional care or live horse work.

Bring your compliance questions.

We're happy to walk your team through the safeguard model, consent flows, and deployment requirements in detail.

Talk to us