Security and responsible AI

Trust needs evidence, not a badge wall.

Ethiya is designed to protect home-care information through clear boundaries, accountable access, auditable workflows, and AI controls that remain part of the product—not an exception to it.

Operations / Access reviewRiverside branch DP
PERMISSION-AWARE ACCESSRole boundaries
Active policy
WorkflowCoordinatorCaregiverFamily
ScheduleManageAssignedShared
Care noteReviewAuthor
BillingView
AI draftApprovePrepare

Family update approvedJamie Chen · 10:21 AM · source retained

Audit record
Illustrative product view

What changes

Know what is in scope.

Security and compliance statements should identify the service, environment, data, customer responsibility, third party, and date they cover. Ethiya will not use a contract, vendor claim, or framework name to imply broader assurance than it provides.

Connected capabilities

Each part of the workflow keeps its context, boundaries, and accountable owner.

01

Access and organization boundaries

Ethiya's security review covers:

  • organization and location isolation
  • role- and permission-based access
  • privileged administrative access and review
  • authentication and session controls
  • user lifecycle and access removal
  • audit records for sensitive actions
02

Data protection

Ethiya's security review covers:

  • encryption in transit and at rest
  • secure key and secret management
  • protected backups and tested recovery
  • data retention and deletion controls
  • secure development and vulnerability management
  • incident response and customer notification process
03

Responsible AI

AI does not grant access to records or fields the user and workflow could not otherwise access.

  • Generated, rewritten, translated, summarized, or scored content is distinguishable where it affects review or action.
  • Source records remain available for review, and accountable people approve consequential use.
  • Each automated workflow has defined inputs, permitted actions, escalation conditions, and history.
04

Provider transparency

Ethiya documents which model or service categories process customer data, their role, retention and training terms, and applicable contractual safeguards during security review.

05

Monitoring and review

High-impact features require quality evaluation, failure analysis, access review, and a way for users to report a wrong or unsafe result.

Shared responsibility

Shared responsibility

Ethiya protects the service and provides controls. Agencies remain responsible for user access, configuration, recipient authorization, channel consent, device practices, workforce policy, and the professional decisions made with the system.

Questions to ask

Clear answers belong in the evaluation.

Is Ethiya HIPAA compliant?+

Ethiya supports HIPAA-aligned operations through scoped safeguards and agreements. Whether a customer's use meets HIPAA requirements depends on the deployed service scope, contract, agency configuration, and shared responsibilities. Ethiya provides the exact scope during security review rather than making an unqualified certification claim.

Does Ethiya use customer data to train public AI models?+

Ethiya documents the provider, retention, training, and data-use terms that apply to each production AI workflow during security review. Those production terms—not architecture intent—define how agency data is handled.

Where is Ethiya data hosted?+

Hosting region, resilience, backup, and subprocessor details are provided for the production environment during security review.

Which certifications does Ethiya have?+

Ethiya lists only completed, current certifications or independent assessments with their exact scope. Ask for the evidence currently available for the service under review.

See it in context

Review the evidence that applies to you

Security questionnaires, architecture information, data-flow details, subprocessor information, and contractual materials are available through a controlled review process.

Start a security review