Soli
Security Guide

Understanding Encryption

How Soli protects your patient data, explained in plain language. No technical background required.

What encryption means in plain language

Encryption scrambles information so that only the intended recipient can read it. Picture a letter sealed inside a locked box. Anyone can carry the box from point A to point B, but only the person holding the key can open it and read what is inside. Without the key, the contents are indecipherable.

Soli encrypts every piece of patient data that passes through its systems — form submissions, text messages, voicemail recordings, voicemail transcripts, and AI call transcripts. Data is scrambled before leaving the device where it originated and stays scrambled until it reaches your authorized device, where it is unscrambled for reading.

How Soli Forms protects submissions

Here is what happens, step by step, when a patient fills out a form on your website:

The patient completes the form in their web browser — name, contact information, reason for seeking services, insurance details, or whatever fields you have included.

Encryption happens in the browser before the data goes anywhere. The patient's browser uses your practice's public encryption key to lock the data. This is automatic — the patient does not need to do anything special.

The encrypted submission is sent to the server and stored. The server never sees unscrambled data — it holds the locked box without the key.

Only your device can open it. When you launch the Soli Forms application, your private encryption key — which exists only on your device and never leaves it — unlocks the submission for reading.

Your private key is generated on your device at account creation and stored in your device's secure storage. It is never uploaded to any server. This is why Soli Forms uses a local-first architecture — your device is the sole location where the key exists.

How Soli Line protects messages

Soli Line takes a different approach because phone communication must work across multiple devices — your desktop, your phone, and potentially a colleague's device. Here is how it works:

Your login creates a unique key. At sign-in, your password is run through a key derivation process — 600,000 rounds of a mathematical function — to produce a unique encryption key. This key exists only in your device's memory while you are signed in.

Messages are locked with a shared line key. Each phone number has its own encryption key (a line key) that encrypts and decrypts messages on that number. The line key itself is encrypted with your personal derived key and stored on the server in locked form.

Only authorized devices can read them. Signing in on any device — desktop or mobile — derives the same key from your password. That key unlocks the line key, which unlocks your messages. The server stores everything encrypted and cannot read any of it.

If you lose your phone, your messages remain safe. The lost device cannot decrypt anything without your password. Sign in on a new device and your entire encrypted message history is accessible immediately.

What “zero-knowledge” means

"Zero-knowledge" means Soli's servers cannot read your data. The company has zero knowledge of what your encrypted information contains. Soli stores your data, transmits it between devices, and backs it up — but no Soli employee, server process, or automated system can ever read the actual content.

This differs fundamentally from most software labeled "secure." Many platforms encrypt data "at rest" on disk and "in transit" over the internet, yet the company holds the keys and can decrypt your data at will — for support requests, legal demands, or internal analysis. With Soli, the keys live on your devices. Even a compromise of Soli's servers would yield only encrypted data the attacker cannot read.

What a BAA is and why it matters

A Business Associate Agreement (BAA) is a HIPAA-required contract for any third-party service that handles protected health information (PHI). If software touches patient data — names, contact information, treatment details, billing records — the company behind it is a "business associate" and must execute a BAA with you.

The BAA creates legal accountability. The business associate agrees to protect PHI under HIPAA standards, report breaches, and restrict how data is used. Without a BAA in place, using any software tool for patient information puts your practice at risk of a HIPAA violation — regardless of the tool's technical security.

Soli includes a BAA with every subscription. For Soli Line, the telephony infrastructure provider (Telnyx) operates under a separate BAA covering the carrier layer. The entire chain — from the patient's phone call, through the carrier, to Soli's server, to your device — is backed by appropriate legal agreements.

How this is different from other platforms

Most practice management tools store patient data in a form the company can access. They encrypt "at rest" on their servers and "in transit" over the internet, but the company retains the decryption keys. Their employees, support staff, and servers can technically read your patient information. If the company is hacked, the attacker may gain access to readable data.

Soli works differently. Your encryption keys never leave your devices, so the data on Soli's servers is unreadable without them. A server breach would expose only encrypted data — useless without the keys that exist solely on your personal devices. This is the same model used by privacy-focused email and password management services.

In practice, this means you can tell patients with confidence that their intake information, messages, and voicemails are protected by the strongest practical level of encryption available — and that not even the software company can read them.

A note on responsibility

Since Soli cannot access your encryption keys, it also cannot recover your data if you lose access to all authorized devices (in the case of Soli Forms). Choose a strong, memorable password and keep your devices secure. For Soli Line, your password is the foundation of your encryption — any device where you sign in can access your messages, so protect your credentials accordingly.