How Praxis handles practice data. Claims here match what ships today — not a compliance certification.
Traffic uses TLS. Data at rest lives in Postgres (Neon) and object storage (GCS) with provider encryption. Practice AI API keys are encrypted on the server when Practice AI is on.
Each practice is a workspace. Application queries scope by membership. Clients use a separate Client Access path into the portal — not consultant seats.
Neon provides point-in-time recovery for the database. Object storage follows the deployment backup policy.
Directory CSV export and Report PDF/DOCX downloads are available in the workbench. Full practice structured export (text/metadata) is available to platform ops. A customer self-serve full archive is not shipped yet.
Core path: Clerk (sign-in), Neon (database), Google Cloud (app and files), Stripe (practice billing and optional client payments with your keys), and email delivery for transactional notices. Optional Practice AI calls Gemini, OpenAI, or Claude with your keys.
Significant workbench actions write audit events (issue, send, portal fulfill, and similar). Sign-in MFA is available through Clerk account settings — Praxis does not invent a second MFA product.
Practice AI is off until an administrator turns it on and stores a key. Draft prompts stay in Praxis for View Prompt; Praxis does not train models on your work. Findings and recommendations stay completable with AI off.