How we keep your data safe.
Aler Intelligence gets the attention. The encryption, the append-only audit log, the account isolation, and the sign-in rules are what make it worth trusting. Here is the unglamorous machinery, described plainly, and honestly about what is built and what is not yet.
The controls that are actually running.
No single failure should be enough to expose a record. These are built and live right now.
Encrypted at rest
Sensitive fields are encrypted one by one in the database, on top of encrypted storage volumes. Keys are held server-side and can be rotated, and backups are encrypted with a separate key.
Encrypted in transit
Everything moves over TLS, HSTS is enforced, and the backend refuses plain HTTP in production.
An append-only audit log
Every read and write of a record is logged. The application can only add to that log; it holds no permission to edit or delete a single line of it.
Least privilege by default
Every request is checked against the caller’s role. Support staff cannot see health data by default, and any access is itself logged.
Clinicians sign in with two factors
A clinician using a password must clear a second factor, enforced on the server. Patients sign in through Google or Apple, so there is no Aler password to steal.
No secrets in the logs
Identifying fields are reduced to opaque IDs before anything is logged. Model provider keys live only on the server and are never sent to the browser.
Your record stays in your account.
Your data is isolated per account, and your baseline is computed from your own history only. Health data does train our models, and every record that reaches training is de-identified first. Identifiable data never leaves your account for that or for any other purpose.
On the clinical side the rule is stricter: a clinician at one practice sees only what that practice’s link to you allows, even if the same clinician also works somewhere else that treats you. The default is isolation, and it is never relaxed on its own. When there is no link, Aler behaves as if the record does not exist, so nothing leaks by absence.
Anything used for training or research lives in a separate, structurally de-identified store with no link back to your account. More on that in Privacy.
The log is the receipt.
Because every read and write is logged in an append-only record, we can reconstruct exactly what happened, who touched what, and when. That is the foundation of an honest response.
If a breach affects you, we notify the people affected within HIPAA’s 60-day window, sooner for anything material, and we notify supervisory authorities within 72 hours where GDPR applies. For a material incident we publish a plain-language summary of what happened and what changed because of it.
We do not claim what we have not earned.
Aler is HIPAA-aware: the codebase is built around the HIPAA Security Rule’s technical safeguards. On the clinical side, practices sign a Business Associate Agreement before any patient data is shared. That is not the same as a formal certification, and we will not pretend otherwise.
In place
HIPAA-aware technical safeguards (encryption, audit logging, access control, mandatory clinician two-factor). Business Associate Agreements with practices on the clinical side.
On the pre-launch roadmap
A formal SOC 2 audit, HITRUST, third-party penetration testing, and single sign-on and passkeys for practices. These are planned, not yet earned, and we will say so until they are done.
Vendor security questionnaires and due-diligence requests go to [email protected]. We answer most within a week.
Found something? Tell us first.
Safe harbor
Good-faith research done under our disclosure policy is welcome, and we will not pursue legal action against researchers who follow it.
Report it
Email [email protected]. A PGP key is available on request, and we acknowledge reports within 24 hours.
Coordinated, not bountied
We do not run a paid bounty program yet. The terms are in our Vulnerability Disclosure Policy.
Questionnaires, reports, or a vulnerability. Same inbox.
One address handles vendor due diligence and security reports. Most questionnaires come back in under a week, and credible security reports are acknowledged within 24 hours.
Last updated July 2026.
Continuously monitor your health.
Aler Health pulls your whole health together and tells you what actually matters. Download it today and let's optimize your health, once and for all.
Wearables, blood work, medicines, supplements, DNA, even the air around you, read together.
Aler learns what's normal for you, then watches for the moment your numbers start to slip.
When something moves, you hear what changed and what to do next, with no charts to decode.
Not ready to download? Get an occasional email as Aler grows. No spam, leave anytime.
