> For the complete documentation index, see [llms.txt](https://docs.rooks.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.rooks.ai/trust-and-accessibility/how-rooks-protects-your-data.md).

# How Rooks Protects Your Data

Rooks uses secure storage, controlled access, and separation between form creation and response collection to protect your information.

### HIPAA-compliant response storage

Rooks supports HIPAA-compliant collection and storage of form responses, including answers and files uploaded by the person completing the form.

Business Associate Agreements are available for qualifying customers. Contact us if your organization requires a BAA.

Rooks is also SOC 2 Type II certified.

### Keep form creation separate from response collection

The form assistant helps you create, edit, and style a form. Once the form is published, it runs using the questions and conditional rules you approved.

No language model is involved while a person completes the published form. Their answers are handled by the response-storage system rather than the form assistant.

{% hint style="warning" icon="square-exclamation" %}
**Keep PHI out of the form assistant**

Do not include protected health information in conversations with the form assistant or in source files uploaded to it. Use fictional examples, placeholders, or de-identified information when describing the form you want to create.

This restriction applies to the form-building process. It does not prevent a published form from collecting information through Rooks’ HIPAA-compliant response-storage system.
{% endhint %}

### Restrict access to responses

Rooks requires users to sign in before accessing a workspace. Workspace roles and form-specific access policies determine who can view forms, edit them, or work with their responses.

Owners and Admins can limit response access to the individual team members or groups that need it. Editing access is managed separately and can only be assigned to one person at a time.

See [Roles and Permissions](/workspace-and-team/roles-and-permissions.md) for instructions on controlling access.

### Protect answers and uploaded files

Rooks automatically stores answers and uploaded files as a person progresses through a form.

Uploads use temporary, signed access instructions tied to the correct workspace, form, and published version. Files displayed through the response interface also use protected, time-limited access rather than permanent public links.

### Keep response data out of usage analytics

Rooks separates product-usage reporting from customer response data. Usage analytics are designed to exclude:

* Answers and response contents.
* Names and contact information.
* Respondent identifiers.
* Uploaded file names and storage locations.
* IP addresses and device information.
* Form or question labels that could contain sensitive information.

Rooks rejects unsupported usage metadata that could introduce protected health information into the analytics system.

### Verify webhook deliveries

Rooks signs webhook deliveries so a connected system can verify that a request came from your workspace.

Admins and Owners can retrieve the workspace’s signing key from **Workspace settings** → **Security**. If the key may have been exposed, it can be rotated and replaced in the receiving system.

Rotating the key immediately invalidates the previous one. Rooks retries unsuccessful webhook deliveries for up to 12 hours, giving you time to update the connected system.
