SOC2C

Is this your company? Buyers are checking AlayaCare here. Claim alayacare.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
AlayaCare logo

AlayaCare

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

AlayaCare is SOC 2 Type II compliant. AlayaCare also holds HIPAA, HITRUST, and CSA STAR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Data security and privacy are core values at AlayaCare. We build them into our organization, our processes, and into the home care software platform we deliver. Our Trust Center is just one of the ways by which we demonstrate how we protect your most valuable asset. Please refer to the FAQ section link below for more detailed information regarding AlayaCare's security and privacy protections.

Compliance & infrastructure

SOC 2 Type IIHIPAAHITRUSTCSA STAR
Hosting
AWSGCP

Subprocessors

9
  • A
    Amazon Web Services · Cloud provider
    Same region as customer region (USA, Canada, Australia)
  • C
    Cloudflare · Cloud monitoring
    Same region as customer region (USA, Canada, Australia)
  • W
    Wiz · Security
    Same region as customer region (USA, Canada, Australia)
  • S
    Snowflake · Data storage and processing
    Same region as customer region (USA, Canada, Australia)
  • E
    ElevenLabs · Engineering
    Same region as customer region (USA, Canada, Australia)
  • O
    OneSchema · Data storage and processing
    Same region as customer region (USA, Canada, Australia)
  • G
    Google Cloud · Data analytics
    Same region as customer region (USA, Canada, Australia)
  • B
    Box · Data storage and processing
    Same region as customer region (USA, Canada, Australia)
  • S
    Sendbird · Collaboration
    Same region as customer region (USA, Canada, Australia)

Compliance leadership

The person who leads AlayaCare's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. AlayaCare's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Alayacare Cloud SOC2 report 2025 is ready!Oct 2025

Our latest SOC 2 Type II report (2025) is now available to AlayaCare Cloud customers. To access: sign in to the Trust Center and navigate to Resources. SOC 2 reports for Alayacare Residential and Procura CS will follow in the next days. Need help? Contact security@alayacare.com or your Customer Success Manager.

🚀 New Whitepaper Available on Our Trust CenterMay 2025

Secure and Streamlined Authentication: Leveraging Your IDP with AlayaCare Cloud We're excited to share our latest whitepaper exploring how organizations can enhance security and user experience by integrating their Identity Provider (IDP) with AlayaCare Cloud. This guide outlines best practices, implementation tips, and key benefits of a federated authentication model to streamline access while maintaining robust protection for sensitive healthcare data. 📄 Now available on the Trust Center using this link.

2024-2025 Compliance documentation available!Feb 2025

Our compliance docs have been refreshed. - New SOC 2 reports for AC Cloud and AlayaCare Residential (2024) - New SOC 1 Report for AC Cloud (2024) Stay tuned for more compliance updates.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is AlayaCare SOC 2 compliant?
AlayaCare is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is AlayaCare HIPAA compliant?
According to AlayaCare's public trust center, AlayaCare is HIPAA compliant. On SOC2C this listing is Listed.
Is AlayaCare HITRUST certified?
According to AlayaCare's public trust center, AlayaCare is HITRUST certified. On SOC2C this listing is Listed.
Is AlayaCare CSA STAR certified?
According to AlayaCare's public trust center, AlayaCare is CSA STAR certified. On SOC2C this listing is Listed.
Is AlayaCare SOC 2 Type I or Type II?
AlayaCare is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.

Answers published by AlayaCare

Reproduced from AlayaCare's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Audit Logs
AlayaCare's SaaS platform maintains audit logs and audit trails of (i) a comprehensive set of user activities performed in the application, and (ii) access to the application within the secure infrastructure of the Customer's AWS instance/tenant. As audit logs and trails become a bigger part of healthcare and privacy regulation, AlayaCare takes a comprehensive but user-driven approach to many audit inquiries. Via in-app clinical functions, user can audit activities along with changes to user roles and permissions. This overview of the elements of AlayaCare's capabilities can serve as a baseline from which Customers can map to their specific requirements and use cases. Some additional configurations can be implement upon request by AlayaCare's professional services and data management teams. More detailed information can be access through this requestable document: https://trustcenter.alayacare.com/resources?s=jp6i11wg5fbz8rmjsagkn&name=alayacare-core-audit-logging-and-related-capabilities-xlsx
Does AlayaCare support SAML SSO?
AlayaCare supports all SAML 2.0 Identity Providers for Single Sign-On (SSO)
Privacy Policy
AlayaCare’s Privacy Policies describe how we address the privacy and security of the data and other information entrusted to us: - by our customers through their access and use of the AlayaCare electronic health record platform; - by our business partners and specific third-party providers of key services to us; and - by everyone else, including partners, prospective customers, and those who seek information or contact us through our website.
Privacy & Data Management
Overview Privacy and data protection practices at AlayaCare complement the core security infrastructure and tools that ensure the integrity of the personal and protected health information in AlayaCare's custody. Using a shared-responsibility model, individual consents and requests for access are managed by AlayaCare's customers. AlayaCare, in its capacity as a business associate or data custodian, assumes responsibility for the integrity and redundancy of the data in its secure, AWS cloud-based infrastructure. A data map sets out the key flows of information in and out of the AlayaCare infrastructure; https://trustcenter.alayacare.com/resources?s=si6ekbq9ejdwf3031zoxur&name=overview-of-alayacare-system-architecture-diagram-png Privacy Impact Assessments (PIAs) Assessing the impact of its products and services on the privacy and data of customers is an important component of AlayaCare's approach to safeguarding patient data and maintaining compliance with privacy regulations. AlayaCare's PIA serves as an important evaluation of its data management practices and their impact on privacy. By conducting a thorough assessment, AlayaCare can identify and address potential privacy risks associated with its EHR platform and its key functional capabilities. This proactive approach allows AlayaCare to ensure that the confidentiality, integrity, and availability of the health information maintained in our platform are effectively protected. Key benefits of AlayaCare’s PIAs include: 1. Privacy Compliance: A PIA enables AlayaCare to assess its compliance with applicable privacy laws and regulations, such as the Health Insurance Portability and Accountability Act (HIPAA) in the United States and the Personal Health Information and Protection Act (PHIPA) in Ontario. By conducting a PIA, AlayaCare can identify any gaps in compliance and implement necessary measures to meet regulatory requirements. 2. Risk Identification and Mitigation: The PIA process helps AlayaCare to identify…
Business Continuity
AlayaCare's electronic health records platform uses a variety of tools and mechanisms to achieve high availability and resiliency. Its infrastructure spans multiple fault-independent AWS availability zones in geographic regions physically separated from one another. AlayaCare’s infrastructure is able to detect and route around issues experienced by hosts or even whole data centers in real-time and employ orchestration tooling that has the ability to regenerate hosts, building them from the latest backup. AlayaCare also leverages specialized tools that monitor server performance, data, and traffic load capacity within each availability zone and colocation data center. If sub-optimal server performance or overloaded capacity is detected on a server within an availability zone or colocation data center, these specialized tools increase the capacity or shift traffic to relieve any suboptimal server performance or capacity overload. AlayaCare is also immediately notified in the event of any sub-optimal server performance or overloaded capacity.

Business & Industrial peers that completed SOC 2