Security

How Aulia protects data

Aulia holds children's health records, staff files and a practice's finances. These are the safeguards in place today.

Where the data lives

Aulia runs on Amazon Web Services in the United States (Oregon region). Data is encrypted in transit with TLS and at rest with keys managed in AWS Key Management Service. Stored files such as signed documents are kept in private, encrypted storage and are only reachable through the application.

Who can sign in, and what they see

A record of access

Viewing and changing records is written to an audit log, so the practice can see who opened or edited what, and when. Clinical records are corrected by adding a dated correction, not by silently overwriting what was signed.

AI features

Aulia's AI features — such as drafting a note from session data or reading an explanation of benefits — run only on Amazon Bedrock, inside the same AWS account and covered by Amazon's Business Associate Agreement. Client information is not sent to any AI service outside that agreement, and is not used to train AI models.

Bank connections

When a practice connects its business bank accounts, the sign-in happens inside Plaid and Aulia never receives bank passwords. The connection token Plaid returns is encrypted (AES-256) before it is stored. Aulia only reads account and transaction information; it cannot move money. A practice can disconnect a bank at any time.

Sharing outside Aulia

Records are never sold and never used for advertising. Information leaves Aulia only to do the practice's work — for example, a claim sent to an insurance clearinghouse, or a fax to a provider the family has authorized — and only through services the practice uses for that purpose.

Reporting a concern

If you believe you've found a security problem, please email us. We read every report and will reply.