Trust center
Attuniva holds health information for wellness practices, so this page states plainly what protects it, who can see it, and what we have not built yet. Where a control is partial, it says so.
Someone’s health history is the most private thing they will ever hand you. We treat it that way.

Implemented controls
Each control below is implemented in the product now, labelled with the SOC 2 criterion it serves.
Logical access
Access rules are enforced per record by the platform, not by the screens that read them — so a practice cannot reach another practice's clients, notes or money through the API either. Writes are scoped the same way, since planting a record inside another practice is the same breach arriving from the other direction.
Logical access
Reading a health record, exporting a client's data or asking the AI about a practice all prove membership and permission server-side, from active role assignments. The practice named in a request is treated as a claim to be checked, never as a fact.
Monitoring
Each recorded access is hash-chained to the one before it within a practice, so altering or removing a past event breaks every hash after it and is reported at the exact point of change. Nobody — including platform staff — can edit or delete an audit event.
Confidentiality
Session notes, assessments, signed waivers, intake submissions and incident reports cannot be deleted by any practice user. A signed note cannot be rewritten; it is amended. Lawful erasure runs as a reviewed server process instead.
Privacy
A subject request is logged with the statutory clock running from receipt, and completion writes a receipt the practice cannot edit: what was purged, what was pseudonymised, and what was retained with the legal ground named. Records that law requires us to keep are pseudonymised rather than quietly deleted.
Privacy
All email leaves through a single sending path that applies suppression, consent, frequency caps and the required footer. An unsubscribe is honoured immediately and cannot be undone by a later import.
Confidentiality
Audit detail records field names and counts, never clinical content. Notifications carry no health information. Shared AI caching is scoped so one practice's generated content can never be served to another.
Availability
Background engines propose to the practice owner rather than acting silently, spend against a hard per-practice ceiling, and step down when it is reached. A practice owner can suspend all autonomous activity outright.
Sub-processors
Every third party that can access personal data on our behalf, and exactly what each one sees.
| Processor | What it does | What it can see |
|---|---|---|
| Base44 | Role: Application hosting, database, authentication, file storage | Sees: All application data, including health records |
| Resend | Role: Email delivery | Sees: Recipient name and address, message content, engagement events |
| Wix Payments | Role: Payment processing | Sees: Payer name, billing details, amounts. Card data never reaches Attuniva |
| LLM providers (via the platform AI gateway) | Role: AI drafting, summarisation and clinical assistance | Sees: Only the content a practice submits to an AI feature, for that request |
Data location
Stated per party, including the two places we have not been told a named region — because a guess is the one thing a reviewer would rely on.
The hosting platform's region; not confirmed to us as a named region
We do not choose or control the storage region, and there is no per-practice residency setting. A practice under a residency obligation should ask us before storing records here.
United States
Recipient addresses, message content and engagement events leave the practice's own region to be delivered. This applies to reminders and marketing alike.
Determined by the payment provider
Payer name, billing details and amounts are processed under the provider's own terms. Card numbers never reach Attuniva.
The model provider's region; not confirmed to us
Only the content submitted with a request is sent, and only for that request. A practice that must keep clinical text in one jurisdiction should not use the AI clinical features.
| What | Where it is processed | What that means |
|---|---|---|
| Attuniva application and database | The hosting platform's region; not confirmed to us as a named region | We do not choose or control the storage region, and there is no per-practice residency setting. A practice under a residency obligation should ask us before storing records here. |
| Email delivery (Resend) | United States | Recipient addresses, message content and engagement events leave the practice's own region to be delivered. This applies to reminders and marketing alike. |
| Payment processing (Wix Payments) | Determined by the payment provider | Payer name, billing details and amounts are processed under the provider's own terms. Card numbers never reach Attuniva. |
| AI features (platform AI gateway) | The model provider's region; not confirmed to us | Only the content submitted with a request is sent, and only for that request. A practice that must keep clinical text in one jurisdiction should not use the AI clinical features. |
Where a transfer leaves the UK or EEA, it rests on the sub-processor's own standard contractual clauses rather than on any mechanism Attuniva has entered into directly. We have not completed transfer impact assessments, and we do not offer a region choice, so a practice with a strict residency requirement should treat that as unmet today rather than assume it is handled.
Open items
Published because a trust center that lists only strengths is not evidence of anything.
A practice can record its own executed business associate agreements here, but Attuniva does not currently offer a platform BAA, and the sub-processor BAA chain is not confirmed. Until both exist, a covered entity should treat the technical controls as present and the contracts as outstanding.
The controls above are implemented and testable, but they have not been examined by an outside auditor. This page is our own account of them, not an attestation.
Staff see their practice's clients, which is what a front desk needs to work. Narrowing clinical reads to the practitioner treating a given client is in progress.
Data is stored in the hosting platform's region, which we do not choose, so there is no per-practice region setting — offering one that did not move data would be worse than the gap. The Data location section above states what we know and what we have not been told.
We do not yet publish measured availability, so we make no uptime commitment. Stating a number we do not measure would be worse than the gap.
Reporting
If you believe you have found a vulnerability or a privacy problem, contact your practice’s administrator, who can raise it with us directly. We would rather hear about a suspected issue that turns out to be nothing than not hear about a real one.