Business context only
Organization, role, review trigger, approximate AI scope, deadline, and contact information.
Trust & security
How Ayliea handles assessment evidence, where the data boundary sits before scoping, and where to find the documents that govern an engagement.
Source last verified by Ayliea: 28 July 2026 · Copy last reviewed: 21 August 2026
Data boundary
The booking page and initial email are for scoping only. Do not include patient records, PHI, credentials, questionnaires, configuration exports, contracts, or assessment evidence.
Organization, role, review trigger, approximate AI scope, deadline, and contact information.
Engagement evidence is exchanged only after scope, contractual terms, access, and handling expectations are established.
PUBLISHED FACT · Assessment scoping and evidence collection
Ayliea's published posture is to assess controls, configurations, and evidence without requesting or ingesting patient records. PHI should remain in the customer's environment.
PUBLISHED FACT · Engagement-specific
Ayliea states that it will execute a customer BAA or provide its own when an engagement requires one or customer policy calls for one.
PUBLISHED FACT · Contracted engagements
Architecture details, vendor lists, configuration exports, and interview notes are treated as engagement material and governed by the applicable confidentiality and engagement terms.
PUBLISHED FACT · Customer and engagement data
Ayliea's current public policy states that customer data is not sold and is not used to train models. Any engagement-specific processing remains subject to the applicable agreement and disclosure.
PUBLISHED FACT · Initial contact
Security concerns may be sent to security@ayliea.com and privacy or data-rights questions to privacy@ayliea.com. Sensitive evidence should not be included in an initial message.
Evidence lifecycle
Request only the artifacts reasonably needed for the agreed procedures and scope.
Use the approved engagement channel—not booking, public forms, or an unsolicited email attachment.
Limit engagement evidence to authorized personnel and disclosed service providers with a delivery need.
Apply the applicable agreement and engagement-specific retention or deletion terms.
DOCUMENTS
Sub-processors, retention terms, and disclosure procedures are documented in full in the linked sources below rather than repeated here—those documents are the source of truth.
Claim boundary
This site does not claim that Ayliea is SOC 2 certified, independently penetration tested, or certified against an information-security standard.
Future assurance claims should be added only with current evidence, scope, date, and an appropriate public or available-on-request source.
SECURITY & PRIVACY CONTACTS
Send suspected vulnerabilities to security@ayliea.com. Send data-protection inquiries to privacy@ayliea.com. Do not include exploit details, PHI, credentials, or sensitive evidence in the first message.