Trust & Safety
Safety is the product, not an afterthought.
Citt.ai is therapist-supervised practice software: every client message is screened for risk before the AI replies, therapists stay in control of care, and sensitive data is handled with encryption, access controls, and auditable records. We publish safety goals and measured checks — not marketing guarantees.
Safety goals we design around
We test these goals with automated safety checks that include crisis messages, safe reassurance, and attempts to phrase risk indirectly. We also run an internal multi-turn evaluation (CEP v3) on curated offline transcripts to review assistant behaviour across a conversation — those results are not published as live guarantees.
Latest published safety check
When a safety check has been published from the production reporting system, we show whether it met the safety goals rather than presenting any test result as a guarantee of perfect safety.
How Citt.ai keeps client support safe
Four layers work together: deterministic risk screening before any AI reply, therapist oversight, accountable records, and privacy-sensitive infrastructure.

Risk checks before AI replies
Client messages are checked for signs of suicidal thoughts, self-harm, abuse, severe distress, and other urgent risk before the AI response is generated. The same principle applies across client chat, WhatsApp, voice-derived captions, and other client-facing routes.
Therapists stay in control
Citt.ai supports the therapist–client relationship. Therapists review activity on their schedule, approve clinical content, and receive alerts when urgent risk is detected — without a 24/7 monitoring obligation.
Accountable record keeping
Important safety events and clinical actions are recorded with time, user, and context so the care team can understand what happened. Crisis events create a care record and therapist notification.
Privacy-sensitive infrastructure
Production data is hosted on AWS in eu-west-2 (London) with encryption, role-based access, and contractual controls on third-party service providers. AI providers process only what is needed for the feature you use.
Tested against the ways risk can be missed
We test more than obvious crisis phrases. The suite includes disguised wording, attempts to push the AI toward unsafe advice, and conversations where risk builds over several messages. We publish these areas separately because they are harder than direct crisis detection and should not be overstated.
How we test assistant behaviour across a conversation
Production crisis screening runs on every live message (Mode A). Separately, we run an in-house adversarial multi-turn programme (CEP v3, Mode B) on simulated transcripts to review how assistant replies behave when risk builds or is disguised across several turns. That work uses anchored criteria — harm validation, empathy pacing, escalation timing, tier-appropriate routing — not a single headline score.
July 2026 campaign
A high-risk offline campaign across 47 scenarios completed with zero critical or actively-damaging failures at the final gate. That is an in-house measurement, not third-party certification.
August 2026 clinician pilot
Licensed clinical advisor Daniel Goldstone annotated a small sample (15 cases, 5 scenarios) from an offline gpt-5.4 pilot run. All critical harm-validation criteria were satisfied; majors clustered on empathy pacing and locale-aware resource routing. This begins clinician review; it is not full Phase 12 validation. We do not treat this small pilot as a platform accuracy or certification claim.
We do not publish multi-turn pass rates as certification claims until methodology version, corpus identifier, and run date are wired to a public artifact. Detailed corpora stay in internal and NDA evidence packs.
Where we are careful about claims
How client records are created
Therapists can run their full practice in Citt.ai, including for clients who have not yet signed in to the client portal. We gate every client-facing feature behind an explicit claim step and keep AI access linked to a therapist or clinic that is responsible for the clinical purpose and oversight model.
Managed records
A therapist on Practice or Full Practice can add a client by name and email. The record supports scheduling, notes, billing, and transcription. Until the client claims, no chat, check-ins, assessments, or WhatsApp messages are sent to them.
Claim attaches identity
When the client is ready, the therapist sends a secure, single-use invite link. Claiming attaches the client's sign-in details to the existing record. We do not create a second account or duplicate the data.
No practice can see another practice's data
If the same email is already connected to another therapist, Citt.ai does not reveal that relationship. Any approved linking is logged, and claimed clients can be notified about access changes.
Who is responsible for care and platform operations
For client-facing AI flows, the therapist or clinic remains responsible for the clinical purpose of care. Citt.ai provides the secure platform, safety checks, hosting, trusted service providers, and retention controls. Client chat, check-ins, and assessments are not standalone therapy outside your relationship with your clinician; they stay linked to that clinician or clinic.
Practical supervision expectations
Therapists set the review cadence and response pathway for their practice. Citt.ai screens messages before AI replies and raises urgent alerts, but it is not a live monitoring service or an emergency service. Client access begins through the practice's invitation and consent flow.
Do you verify that therapists are licensed?
Citt.ai is for licensed therapists, mental health professionals, and authorised clinic representatives. During signup, therapists confirm that they are licensed and accept the therapist terms, which require accurate licence and registration information. Citt.ai may verify eligibility and may suspend access if verification fails.
Is Citt.ai standalone therapy?
No. Citt.ai is therapist-supervised practice software and between-session support. Client-facing AI stays linked to a therapist or clinic responsible for the clinical purpose and oversight model. Citt.ai does not provide clinical services, replace professional judgement, or act as an emergency service. Clients can read the client terms for the same boundary in client-facing language.
Are session recordings stored?
Uploaded transcription audio is processed ephemerally and is not intentionally retained after processing. Citt.ai stores the resulting transcript and related metadata. When real-time transcription is enabled, audio streams are sent to the transcription provider while the feature is running. The retention summary is in our privacy policy.
Are transcripts and clinical notes stored?
Yes. Transcripts, speaker segments where available, clinical notes, summaries, assessments, check-ins, and related client-care records are stored so therapists can review care history, generate notes, prepare for sessions, and maintain records. Transcript access and updates are audited.
Can therapists export records if legally required?
Record access and export requests are supported through the therapist or clinic and Citt.ai. Requests involving clinical records are usually led by the therapist or clinic, with platform assistance from Citt.ai. We do not describe this as a one-click self-service legal export today. The routing is explained in the therapist privacy information.
What can clients request or delete?
Depending on location, clients may request access, correction, erasure, export, restriction, or objection to certain processing. Clinical-content requests are normally handled by the therapist or clinic with Citt.ai support. Some records may be retained or archived for clinical-record, billing, safety, security, or legal reasons. WhatsApp and Facebook-linked requests can also start from the data deletion page.
Who owns chats, notes, transcripts, and AI insights?
Client conversational data remains the client's content. Therapist-created clinical content and practice records remain part of the therapist or clinic's clinical record, subject to the limited rights Citt.ai needs to operate the platform. Citt.ai owns or licenses the platform technology itself and does not claim ownership of user-provided conversation content.
Can therapists use licensed or paid assessment measures?
Citt.ai currently includes PHQ-9, GAD-7, PSS, WHO-5, UCLA-Loneliness, and MSPSS as standard assessment types. Therapists should only upload, copy, or configure assessment content they are legally allowed to use. Citt.ai does not grant rights to paid, restricted, or third-party measures.
What happens if a client sends a crisis message?
Client-facing messages are screened before AI replies. If a crisis signal is detected, Citt.ai returns region-aware crisis guidance, creates a care record, opens a therapist alert, and emails the assigned therapist when contact details are available. Citt.ai is not an emergency service, and therapists remain responsible for their clinical response pathway.
Can safety checks be disabled?
No. Therapists can configure the client support style and persona, but crisis and safety checks are not optional. The therapist terms prohibit attempts to bypass, disable, or interfere with safety or crisis detection outside the product's intended clinical controls.
Does between-session chat create a 24/7 clinical duty of care?
Citt.ai is designed so clients can access AI support between sessions — including evenings and weekends — without turning you into an on-call clinician. You configure the service, review conversations on your schedule, and receive alerts when urgent risk is detected. You remain responsible for your clinical judgement and response pathway, but the product does not require you to monitor chat in real time or respond outside your normal practice hours. See the therapist terms for the full supervision model.
How does WhatsApp messaging work, and where does data go?
WhatsApp is an optional channel for clients who opt in. Messages are processed through Meta's WhatsApp Business API, screened by the same safety checks as in-app chat, stored in the client record for therapist review, and listed in our data-practices table below. Citt.ai is not a HIPAA Business Associate for Meta; therapists should use WhatsApp only with appropriate client consent and in line with their own compliance obligations. Clients can read more in the client privacy information.
Who is responsible if the AI gives unhelpful or unsafe advice?
Citt.ai is therapist-supervised practice software, not standalone therapy. The therapist or clinic remains responsible for the clinical purpose of care and for reviewing AI-assisted interactions. Citt.ai runs safety checks before AI replies, logs important events, and alerts therapists when urgent risk is detected — but AI outputs can still be wrong. Therapists should review client activity, approve clinical content where required, and use their professional judgement. Liability boundaries are set out in the therapist terms and client terms.
What third-party safety evaluation work does Citt.ai do or plan?
Today, live client chat uses deterministic per-message risk screening before the AI responds. We also run an in-house adversarial multi-turn evaluation programme (CEP v3) on curated and generated transcripts to stress-test escalation behaviour, using anchored, criterion-level scoring rather than a single free-floating score. Licensed clinicians independently annotate stratified samples of those offline transcripts (automated scores hidden) — that is our independence path, not a vendor badge. In August 2026 our clinical advisor Daniel Goldstone completed a small pilot annotation of 15 multi-turn cases (5 scenarios) from an offline gpt-5.4 run; all critical harm-validation criteria passed, with product follow-ups on empathy pacing and locale-aware resources. That pilot is not full Phase 12 validation. On this sample, critical harm-validation criteria were satisfied in that reviewed sample; overall agreement is not presented as a certification statistic. We are documenting the review path and next steps on our evidence roadmap. Nothing here should be read as an endorsement, certification badge, or third-party validation until a formal programme is completed and we publish the outcome, methodology, and corpus details on our evidence roadmap.
Data Practices
We are transparent about which services help operate Citt.ai and what each service is used for. Data processing agreement materials are available for customer review on request.
| Service provider | Purpose | Data handled | Location | Safeguard |
|---|---|---|---|---|
| AWS (database and storage) | Database and object storage | Account data, client-care data, files, logs | eu-west-2 (London) | Encryption, access controls, contractual terms |
| OpenAI | AI chat responses, transcription | Conversation content, prompts, transcription payloads | US | Contractual controls, no training on API customer data by default |
| AWS (application hosting) | Application hosting | Infrastructure processing and operational logs | eu-west-2 (London) | Encryption, access controls, contractual terms |
| Stripe | Payment processing | Payment tokens, subscription metadata | US | PCI DSS Level 1 |
| Demo scheduling, optional calendar integrations, and consent-gated website measurement | Demo-booking contact details, calendar metadata, device identifiers, and consented website measurement data | US / EU | Consent gating where applicable, contractual terms, and vendor transfer commitments | |
| Meta (WhatsApp Business) | Messaging channel | Messages (when opted in) | US / EU | Platform terms and data processing commitments |
| Resend | Transactional email | Email addresses, notification content | US | SOC 2, TLS encryption |
| Mailgun | Outbound introductory email | Email addresses, marketing content | EU | SOC 2, GDPR data processing agreement |
| Deepgram | Real-time transcription | Audio streams where transcription is enabled | US | Contractual restrictions and security controls |
Evaluating Citt.ai for your organisation?
We provide full technical documentation, safety architecture whitepapers, and can arrange a clinical review for health system procurement teams.