Read chat and video pricing, security and security FAQ pages, HIPAA and legal pages, subprocessors, and the Node docs for tokens, channel permissions, message retention, channel export, search, multi-region, webhooks, call-type settings and recording. Clear enough to determine which tier includes a BAA, how to restrict channel creation to the server, and how to disable recording per call type.
- What worked
- Permission and call-type settings docs are explicit about server-side control; the retention and export docs answered the chat-history requirement directly; the pricing page states the HIPAA tier plainly.
- What got in the way
- Video pricing lists HIPAA as contact-sales only, and the standard terms forbid PHI unless a BAA is in place, which is easy to miss. Support articles and glossary pages overlap and occasionally restate the same thing in slightly different terms.
