> ## Documentation Index
> Fetch the complete documentation index at: https://support.rivvi.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance

> BAA, Do Not Call, audit log, and data security — Settings → Compliance.

**Settings → Compliance** is the legal and evidence surface: the blocklist, your BAA, the audit trail, and where data lives. Calling hours are not here — they live on [Calling](/account/calling).

## Do Not Call

**Settings → Compliance → Do Not Call list** is the org-wide blocklist. Numbers here are blocked across every program.

Opt-outs captured on a call propagate within about **60 seconds** and block in-flight retries. Anyone who has opted out is not contacted again.

## Audit log

**Settings → Compliance → Audit log** is a seven-year record of compliance-relevant events — opt-ins, opt-outs, and policy edits. You can export it as CSV.

## HIPAA and your BAA

Handling protected health information requires a signed **Business Associate Agreement** between your organization and Rivvi. A BAA is included — it is not an upsell.

The gate is a **signed BAA** (`signed` on file), not the presence of a PDF. PHI outreach — most notably [Echo](/connectors/leadingreach) referral calling — stays off until that signature is in place. Connecting tools and asking questions in chat still work.

You can:

* Complete the BAA during [Teach Rivvi](/get-started/discovery)
* Download the current agreement from Compliance
* Upload a signed PDF, DOC, or DOCX (up to 25 MB) with an attestation. Uploads are encrypted, visible to org admins, and written to the audit log.

Organizations that don't handle PHI are not asked to clear a PHI bar they will never cross.

## Data and security

On the same Compliance page:

* **Storage region** — US East (Virginia)
* **Encryption** — AES-256 at rest, TLS 1.3 in transit
* Retention schedules and the vendor list that can touch PHI — [Trust Center](https://trust.rivvi.ai). Request the sub-processor list under NDA from there.

## Web search

Admins can let the coworker look up public web pages during chat. It is **off by default** and lives on Compliance.

## Outreach guardrails (always on)

* **You approve every launch.** Nothing dials until you click the launch card. See [Runs](/workspace/runs).
* **Opt-outs are respected** — captured on a call, they land on the Do Not Call list.
* **Calling hours** are enforced from [Settings → Calling](/account/calling).

Questions about a security review, a BAA, or data handling: [support@rivvi.ai](mailto:support@rivvi.ai).

## Next

<CardGroup cols={2}>
  <Card title="Calling" icon="phone" href="/account/calling" />

  <Card title="Team" icon="users" href="/account/team" />
</CardGroup>
