AIER Technologies, Inc.
AIER

Security & privacy at AIER Schedule

AIER Schedule handles physician scheduling data for emergency departments. This page explains how that data is stored, who can see it, and how privacy requests are handled. It is maintained by AIER Technologies, Inc. to answer common security and privacy questions about AIER Schedule, and is not an independent audit or certification.

Security contact: security@aiertechnologies.com

No patient data. Ever.

AIER Schedule is a workforce scheduling system. It does not require, request, or store patient information to operate.

What data we hold

CategoryExamplesWhy
Roster dataProvider name, work email, credentials, FTERequired to build schedules
Schedule dataShift assignments, dates, departments, locationsCore product data
Preference dataTime-off requests, shift preferencesProvider-entered
Account dataLogin identifiers, role, organization membershipAuthentication only
Optional contact dataMobile number for schedule notificationsOpt-in only

Access control

  • • Every account is scoped to an organization, and access is enforced at the database layer with row-level security — not only in application code.
  • • Roles are separated: platform admin, organization admin, scheduler, and provider each see a different slice. Providers see their own schedule and their group's published schedule.
  • • Multi-location groups can be scoped by department and location.
  • • Sign-in supports passkeys, magic links, and one-time codes. Passwords are never stored in plain text.

Hosting and encryption

  • • Data is encrypted in transit with TLS and at rest by our hosting and database provider.
  • • The application and database run on managed cloud infrastructure in the United States.
  • • Backups and point-in-time recovery are managed by the database platform.

AI processing and de-identification

  • • Schedule imports and assistant features use third-party AI models.
  • • Provider names are scrubbed and replaced with non-identifying tokens before content is sent to an AI provider, then re-attached locally on return.
  • • AI providers are used under agreements that prohibit training on customer content.

Subprocessors

PurposeData shared
Database, auth, and application hostingApplication data
Email deliveryTransactional notification content
SMS deliveryOpt-in mobile numbers and alert text
Payment processingBilling contact and payment method only — no schedule data
AI model providersDe-identified schedule content only

We provide 30 days' notice of material subprocessor changes on request.

Retention, deletion, and privacy requests

  • • Schedule and roster data are retained for the life of the account.
  • • On written request, organization data is deleted or exported within 30 days of termination.
  • • Individual providers may request access to or deletion of their personal data at privacy@aiertechnologies.com.

Business Associate Agreement

Although AIER Schedule does not require or store patient information, we will execute a Business Associate Agreement on request for organizations whose policies require one. Contact legal@aiertechnologies.com.

Compliance posture

AIER Schedule is not currently SOC 2 certified. We follow the practices described on this page — organization-scoped access control, encryption in transit and at rest, de-identification before AI processing, and least-privilege internal access. We are prepared to complete standard security questionnaires and to execute a BAA. Formal SOC 2 Type II attestation is planned as we expand into health-system contracts.

This page describes app-owner practices and enabled platform capabilities. It is not a certification, an audit result, or a legal guarantee.

Vulnerability reporting

Report suspected vulnerabilities to security@aiertechnologies.com. We acknowledge reports within three business days and will not pursue action against good-faith research.

Shared responsibility

AIER provides

Infrastructure security, organization-scoped access enforcement, encryption, de-identification before AI processing, and audit logging.

Your organization provides

Correct role assignment, prompt removal of departed staff, and internal policy on what schedulers upload.

Need a security questionnaire or a BAA?

Tell us what your IT team requires and we will respond with documentation.