Trust Center
Ayureon, Inc. operates a healthcare interoperability platform. We move sensitive clinical data — so trust is the product. This page summarizes how we approach privacy, security, and compliance, and links to the detailed policies that govern our practices.
Who We Are
Ayureon, Inc. is a U.S. company headquartered in Austin, Texas. We design and operate the Ayuva® interoperability platform, including the public API at api.ayureon.com, online appointment scheduling offered by pharmacies and clinics under their own brand, and supporting services.
Privacy
- We do not sell personal information.
- We support patients' rights under HIPAA — access, amendment, accounting of disclosures, restrictions, confidential communications, and revocation of authorization — working with the healthcare providers who hold those records.
- We honor consumer rights under CCPA/CPRA and other state consumer privacy laws.
- We honor Global Privacy Control (GPC) signals.
- We do not use advertising pixels or third-party marketing trackers on pages where health information is entered or displayed.
See the full Privacy Policy.
Security
- Encryption at rest (AES-256) and in transit (TLS 1.2+).
- Role-based access with minimum-necessary enforcement.
- Audit logging of access to health information, enforced at the code level.
- Workforce training on HIPAA and cybersecurity.
- Documented incident response and breach notification procedures.
See the full Security overview.
Compliance Posture
Ayureon, Inc. designs its systems to align with:
- HIPAA Privacy Rule (45 CFR Part 160 and 164, Subparts A and E).
- HIPAA Security Rule (45 CFR Part 164, Subparts A and C).
- HITECH Act breach notification requirements.
- CCPA/CPRA and analogous state consumer privacy laws.
Ayureon, Inc. acts as a HIPAA business associate under written Business Associate Agreements with the covered entities it serves.
Network Participation
The Ayuva® platform exchanges clinical data with connected health information networks, including eHealth Exchange, with additional network participation (CommonWell Health Alliance, TEFCA) on our roadmap.
Subprocessors
Ayureon, Inc. uses vetted subprocessors to deliver platform services. Subprocessors that process PHI are engaged under written agreements, including Business Associate Agreements. All data is processed and stored in the United States.
Responsible Disclosure
If you believe you have discovered a security vulnerability or PHI exposure related to an Ayureon, Inc. service:
- Email
security@ayureon.comwith a description and reproduction steps. - Do not access or download data beyond what is necessary to demonstrate the issue.
- Allow a reasonable window for triage before public disclosure.
Contact
Ayureon, Inc. 12117 FM 2244, Suite 180 Austin, TX 78738
- Privacy:
privacy@ayureon.com - Security:
security@ayureon.com - Legal:
legal@ayureon.com
Document Map
| Document | Where |
|---|---|
| Privacy Policy | /privacy |
| Terms of Service | /terms |
| Security | /security |