Security & Architecture

An intelligence layer that watches the system without ever seeing the patient.

The Practice Intelligence Layer is architected so that protected health information stays inside the practice management system — where it already lives, governed by HIPAA, behind your existing access controls. Sculptrix sees the operational gaps without seeing the people in them.


Pattern 2 Architecture

The layer reads triggers, not patients.

Every patient touchpoint that lives inside an aesthetic practice — names, contact details, treatment notes, photographs, billing records — is governed by HIPAA and stored inside the practice management system. Sculptrix is built so that data never has to leave that system to do its job.

When the layer surfaces an action — a rebooking nudge, a slot-fill match, a follow-up reminder — it does so by passing an anonymized event trigger to the PMS, which executes the patient-facing action through its own existing communication channels. Sculptrix sees the operational pattern. The PMS still owns the patient.

What Sculptrix sees vs. what stays in the PMS

PMS holds
Patient name, contact, history, photos, treatment notes, billing — all of it.
Sculptrix sees
patient_a47f2 · last filler 5mo ago · cycle expected · no upcoming visit
Sculptrix sends
Trigger → PMS → "send rebook nudge to patient_a47f2 via your existing channel"
Patient receives
A message from your practice, through your booking system. Never from Sculptrix.

The pattern eliminates a long chain of legal exposure. The patient relationship stays one-to-one with the practice. The data stays where regulators expect it to stay. And the layer can do its work — finding the gaps, surfacing the moments, orchestrating between systems — without ever becoming a custodian of the information that makes those gaps personal.


The four principles

How the architecture holds.

Principle 01

Data minimization

The layer requests only the minimum signal it needs to identify a revenue gap. Anonymized internal IDs, treatment-cycle metadata, appointment timestamps. Never names, contact details, or clinical notes.

Principle 02

PMS as conduit

All patient-facing communication is sent by the practice management system, using the channels and credentials your practice already trusts. Sculptrix never owns a direct relationship with a patient.

Principle 03

Anonymized identifiers

Patient identifiers passed between Sculptrix and the PMS are opaque references — meaningful only to the PMS, useless if intercepted in isolation. The practice can rotate them at any time.

Principle 04

Practice retains control

Every action the layer recommends is governed by approval thresholds the practice sets. No outbound message, no rebooking attempt, no data write — without owner-defined permission.


HIPAA stance

Where the layer fits in the regulatory map.

Aesthetic practices that perform medical procedures — injectables, lasers, hormone therapy — are covered entities under HIPAA. Patient data stored in a PMS is protected health information. Any vendor that handles PHI on their behalf becomes a Business Associate, with the contractual and operational burden that follows.

Sculptrix is intentionally architected to not be a Business Associate. Because the layer never receives PHI — only anonymized event triggers from the PMS — it operates as a workflow intelligence service rather than a PHI custodian. The PMS retains the BAA relationship with the practice. Sculptrix sits one level above.

This is not a workaround. It's the architecture. The same property that makes the layer legally lighter to deploy is what makes it operationally honest: Sculptrix can only see what the PMS lets it see, and the PMS only lets it see what the practice has approved. The constraint is the moat.


SOC 2 roadmap

Where we are. Where we're going.

Sculptrix is pre-SOC 2 today. We do not represent otherwise to prospects. The roadmap below is committed and dated to our revenue milestones — not to vague "soon" language.

Today
Pattern 2 architecture in production. Pre-SOC 2. Anonymized trigger model documented and reviewable on request. No PHI processed by Sculptrix infrastructure.
First 5 clients
SOC 2 Type 1 audit initiated. Penetration testing scoped. Formal vendor security questionnaire response template published.
$50K MRR
SOC 2 Type 2 in audit window. Annual penetration testing on rotating cadence. Customer-facing security portal live.
National roll-up scale
SOC 2 Type 2 maintained. ISO 27001 evaluated. Per-region data residency on request.

If your practice is part of a private-equity-backed roll-up that requires a vendor-security review before the first contract, we'll meet you in that review with the architecture documentation, the trigger model spec, and a signed confidentiality agreement covering the operational metadata involved. The conversation moves quickly because there's less to argue about: the layer doesn't see the things a Business Associate would have to defend.


Operational security

What we do regardless of certification.

The certifications take time. The security practices do not. Here is what is in production today, independent of the roadmap above:

  • · TLS 1.3 in transit for every connection between Sculptrix infrastructure, the practice management system, and the customer-facing dashboard.
  • · AES-256 at rest on the operational metadata store and all backup snapshots.
  • · Multi-factor authentication required for all Sculptrix admin access. SSO available for customer accounts.
  • · Least-privilege access controls on every internal service. No human ever has standing access to the production database.
  • · Daily database backups with 30-day retention. Quarterly disaster-recovery rehearsals.
  • · All inbound and outbound API requests logged for ninety days. Available to the practice on request.
  • · Incident response policy with named owner, escalation path, and 72-hour customer-notification commitment.

"Permanence is a design choice. One percent of every contract goes to the Snow Leopard Trust, every quarter, on a cadence we won't let drift."

— Sculptrix Impact, 2026

For questions about this disclosure: hello@sculptrix.ai.

Email hello@sculptrix.ai →
Publication

Sculptrix.ai

The Practice Intelligence Layer for aesthetic practices.

Built to be on top.

Set in

Newsreader for display and body. JetBrains Mono for interface and metadata.

Color: cream, ink, oxblood, sandstone, and navy — chosen to last beyond the quarter.

Founders

Briana O'Brien, founder & developer.

Padraic Doyle, chairman & co-founder.

Jennifer Doyle, co-founder & investor.

Filed from Belle Isle, Florida.

Sculptrix  ·  Issue I, No. 02  ·  May 2026  ·  sculptrix.ai