Legal
Asellera Security
At Asellera, security is built into the core of our platform. We employ a defense-in-depth approach to protect the privacy and integrity of clinical data. This page serves as our central hub for transparency, providing insights into our security architecture, compliance posture, and the rigorous measures we take to safeguard every patient interaction.
Updated June 16, 2026
Ontario, Canada
1. Overview
Asellera is built with security as a foundational principle. We design our systems to protect personal information and protected health information (PHI) processed through our platform on behalf of healthcare providers.
Our security program follows industry best practices aligned with HIPAA Security Rule principles and is designed to ensure confidentiality, integrity, and availability of data across all systems.
2. Security Model
Asellera operates a multi-tenant SaaS architecture designed to isolate each healthcare provider’s data.
Each clinic operates within a logically separated environment to prevent unauthorized access or cross-tenant data exposure.
Access to systems and data is strictly controlled and monitored.
3. Data Encryption
All sensitive data is protected using encryption standards designed to safeguard information both in transit and at rest.
Data in transit is encrypted using secure protocols such as TLS 1.2 or higher.
Data at rest is encrypted using industry-standard encryption methods such as AES-256 or equivalent.
Backups and stored archives are also encrypted.
4. Access Controls
Access to production systems and sensitive data is strictly limited.
Asellera uses role-based access control (RBAC) to ensure users only access the data required for their role.
Access is granted on a least-privilege basis.
Administrative access to production systems is restricted, monitored, and logged.
Authentication mechanisms are used to secure all system access, including API access and internal tools.
5. System Monitoring and Logging
Asellera continuously monitors system activity to detect and respond to security events.
Audit logs are maintained for key system actions, including data access, authentication events, and workflow execution.
Monitoring systems are used to detect anomalies, unauthorized access attempts, and system irregularities.
Logs are protected from unauthorized modification or deletion.
6. Infrastructure Security
Asellera systems are hosted using secure cloud infrastructure designed for high availability and resilience.
Infrastructure is configured to follow security best practices, including network segmentation, firewall protection, and restricted administrative access.
Systems are regularly updated and patched to address security vulnerabilities.
7. Application Security
Asellera implements secure software development practices to reduce vulnerabilities.
Security considerations are integrated into the development lifecycle.
Input validation, authentication checks, and secure API design are used throughout the platform.
Sensitive operations require authenticated and authorized requests.
8. Data Isolation
Each healthcare provider’s data is logically separated within the system.
Data is scoped per tenant to ensure no cross-customer access is possible.
Workflow execution, storage, and retrieval are restricted to the appropriate organizational context.
9. Incident Response
Asellera maintains an incident response process designed to identify, contain, and remediate security events.
In the event of a suspected or confirmed security incident:
The issue is immediately investigated and contained.
Affected systems are isolated if necessary.
Impact is assessed and documented.
Healthcare providers are notified without undue delay where required.
Corrective actions are taken to prevent recurrence.
10. Subprocessors Security Requirements
All subprocessors used by Asellera must meet strict security requirements.
Subprocessors are required to:
Maintain appropriate encryption standards.
Implement access controls and authentication mechanisms.
Protect data confidentiality and integrity.
Support secure deletion and retention controls.
Only process data for the purpose of providing contracted services.
11. Data Retention and Deletion Security
Data is retained only for as long as necessary to provide services and meet legal or contractual obligations.
Secure deletion processes are used when data is removed from the system.
Backups and archived data are managed with controlled retention policies and secure storage practices.
12. Employee Access and Training
Access to production systems is limited to authorized personnel only.
Employees with access to sensitive systems or data are required to follow security and confidentiality policies.
Security awareness practices are part of internal operational standards.
13. Compliance Alignment
Asellera’s security program is designed to align with:
HIPAA Security Rule principles
Industry-standard SaaS security practices
Common enterprise security expectations for healthcare software providers
While Asellera may pursue formal certifications in the future, security controls are designed to meet or exceed baseline expectations for healthcare data protection.
14. Updates to This Policy
Asellera may update this Security page periodically to reflect improvements to infrastructure, controls, or compliance posture.
Updates will be posted with a revised effective date.
15. Contact
For security-related inquiries:
Email: privacy@asellera.com
Company: Asellera
Approval
Approved By: Shane Senha, CEO
Company: Asellera
Version: 1.0
Date: June 16th 2026
