A person approves every action
Allayr classifies, prioritizes and suggests. It does not send, file, reply or escalate on its own. There is no autonomous mode, and no setting that turns one on.
Allayr is pre-launch. Rather than a page of badges, here’s a plain account of how the system is built today and where the compliance work actually stands.
Allayr classifies, prioritizes and suggests. It does not send, file, reply or escalate on its own. There is no autonomous mode, and no setting that turns one on.
The application and its database run in AWS ca-central-1. Patient data is not replicated to regions outside Canada.
Access and decisions are written to an append-only audit trail. Records are corrected by adding entries, never by overwriting or hard-deleting history.
Access is enforced at the database level with row-level security, so a query can only ever return rows belonging to the clinic that asked.
It sorts and routes messages. It does not diagnose, advise on care, or perform clinical triage, and it is not a licensed medical device.
We do not describe Allayr as PHIPA or PIPEDA compliant. Formal compliance review is an active track and it is not finished. Saying otherwise would be the kind of claim this page exists to avoid.
What that means in practice, honestly stated:
If your clinic needs specifics for a privacy assessment, ask us directly athello@allayr.com. We would rather answer a hard question than have you infer an answer from a marketing page.
Found something? Email security@allayr.com with enough detail to reproduce it. We’ll confirm receipt and keep you posted on the fix. We won’t pursue legal action against good-faith research that avoids privacy violations and service disruption.
Leave your email and tell us you’re evaluating Allayr. We’ll answer directly — including the parts that aren’t finished yet.