Ashlee Health

Security

Security practices

How Ashlee protects customer and patient data. Last reviewed 2026-08-14.

Our commitment

Ashlee (My Beacon AI Inc.) builds an advance care planning platform that handles sensitive personal health information. We design and operate the service with administrative, technical, and organizational controls intended to protect confidentiality, integrity, and availability.

This page summarizes our public security practices. Customer organizations with signed agreements may receive additional detail under NDA or via their Data Processing Agreement (DPA).

Compliance program

We maintain a continuous compliance program using Vanta, covering SOC 2–aligned and HIPAA-oriented control monitoring alongside our internal security policies.

Security and privacy roles, incident handling, release controls, and key contacts are documented in our internal security handbook and reviewed as the product and organization evolve.

Controls overview

Data residency

Primary application data stores (database and object storage for documents and audio) run in Canada on Amazon Web Services in the ca-central-1 (Montreal) region.

Speech-to-text processing uses Azure Speech in Canada Central. Material cross-border processing paths, when applicable, are disclosed in customer DPA / order exhibits where personal health information is in scope.

Encryption

Data in transit is protected with TLS for public HTTPS endpoints (application UI via CloudFront, API, and related services).

Primary data stores use encryption at rest (AWS-managed encryption for RDS and S3 object storage used by the platform).

Access control

Clinical and administrative access uses authenticated sessions with multi-factor authentication for staff portals.

Cloud administrative access uses AWS IAM Identity Center with named accounts, least-privilege roles, and MFA. Shared root credentials are not used for day-to-day operations.

Application authorization scopes data by organization membership and role so users only see what their role permits.

Network and infrastructure

Workloads run in Amazon VPC with segregated public and private subnets. Application services that process customer data run in private subnets behind load balancers.

Security groups restrict inbound ports to what each service requires. Production databases are Multi-AZ for higher availability.

Infrastructure is managed as code (Terraform and AWS Copilot) with peer-reviewed changes before production release.

Logging, monitoring, and audit

Application and infrastructure logs are retained in Amazon CloudWatch with retention set to support compliance requirements (at least twelve months for in-scope service logs).

Database activity auditing is enabled for the managed PostgreSQL instances (pgaudit). CloudTrail and related AWS audit logs support account-level investigation.

Operational alarms notify on-call operators for critical voice, API, and infrastructure conditions.

Secure development and release

Code changes go through pull requests with review before merge. Production releases follow a documented promotion gate (verification in a non-production environment, then controlled production deploy).

Dependencies and cloud configuration are reviewed as part of ongoing hardening against our compliance backlog.

Incident response

Security events and incidents are tracked in a dedicated private incident repository with severity targets and assigned owners.

External reports (including suspected vulnerabilities) should be sent to support@beaconcare.ai for triage by engineering and operations. Sev-1 issues are treated as immediate / same-day response targets.

Vendors and subprocessors

Core hosting is AWS (Canada). Speech processing uses Microsoft Azure Speech (Canada Central). Other subprocessors used for email, monitoring, or AI inference are disclosed to customers when personal health information is in scope under the applicable DPA.

Contact

Security or vulnerability reports: support@beaconcare.ai

General support uses the same mailbox. Customer security questionnaires and DPA requests can be directed to your Ashlee account contact or vatsal.trivedi@beaconcare.ai.

Related resources

My Beacon AI Inc. (operating as Ashlee Health) · Security information · https://beaconcare.ai/security/