Security Policy

Aivara Health Security Policy




Network Controls

Aivara Health manages, controls, and secures its networks, the connected systems, applications, and data-in-transit to safeguard against internal and external threats.

Firewalls & Threat Defense

Aivara Health must utilize network firewalls, web application firewalls, and/or equivalent mechanisms to safeguard applicable internet connections, internal network zones, and applications from threats. Aivara Health configures appropriate firewall alerts and alarms for timely response and investigation. This also applies to applicable wireless networks. Aivara Health ensures networking ports and protocols are restricted based on the principle of least functionality. Ports and network routes should only be open when there is proper business justification. Firewall configurations and rulesets are maintained. Firewall rules are implemented to minimize exposure to external threats. Significant changes to network services and configurations should be tracked in accordance with the Change Management Policy. As an additional layer of defense, Aivara Health utilizes monitoring solutions to detect and alert on network-based intrusions and/or threats.

Network Diagramming

Satwant Kumar maintains network and data flow diagrams. Diagrams are reviewed and updated when significant network infrastructure changes occur.

Network Access Control

In addition to the Network Security Policy, Aivara Health establishes, documents, and reviews the Access Control and Termination Policy based on business and security requirements. This policy also encompasses network access control. Aivara Health segregates networks based on the required groups of information services, users, and systems. Aivara Health Labs utilizes firewall configurations to restrict connections between untrusted networks and trusted networks. Additionally, Aivara Health may utilize security groups and network access control lists (NACLs) to improve network security for individual virtual machines.

Network Engineering

Aivara Health implements security functions in a layered approach, minimizing interactions between layers of the design and avoiding any dependence by lower layers on the functionality or correctness of higher layers. Aivara Health utilizes a defense-in-depth (DiD) architecture to protect the confidentiality, integrity, and availability of information systems and data, i.e. placing information systems that contain sensitive data in an internal network zone, segregated from the DMZ and other untrusted networks. Aivara Health synchronizes clocks of all applicable information systems to the same time protocol to enforce consistent and accurate timestamping.

Network Service Level Agreements (SLAs)

Security mechanisms, service levels and management requirements of all network services should be identified and included in network services agreements, whether these services are provided in-house or outsourced.

Exceptions

Aivara Health business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other Aivara Health policy. If an exception is needed, Aivara Health management will determine an acceptable alternative approach.

Enforcement

Any violation of this policy or any other Aivara Health policy or procedure may result in disciplinary action, up to and including termination of employment. Aivara Health reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. Aivara Health does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work. Any personnel who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of Aivara Health as soon as possible. The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.

Responsibility, Review, and Audit

Aivara Health reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.

Restrictions

The Parties agree that any arbitration shall be limited to the Dispute between the Parties individually. To the full extent permitted by law, (a) no arbitration shall be joined with any other proceeding; (b) there is no right or authority for any Dispute to be arbitrated on a class-action basis or to utilize class action procedures; and (c) there is no right or authority for any Dispute to be brought in a purported representative capacity on behalf of the general public or any other persons.

Exceptions to Arbitration

The Parties agree that the following Disputes are not subject to the above provisions concerning binding arbitration: (a) any Disputes seeking to enforce or protect, or concerning the validity of, any of the intellectual property rights of a Party; (b) any Dispute related to, or arising from, allegations of theft, piracy, invasion of privacy, or unauthorized use; and (c) any claim for injunctive relief. If this provision is found to be illegal or unenforceable, then neither Party will elect to arbitrate any Dispute falling within that portion of this provision found to be illegal or unenforceable and such Dispute shall be decided by a court of competent jurisdiction within the courts listed for jurisdiction above, and the Parties agree to submit to the personal jurisdiction of that court.

Contact Us

If you have any questions about this Security Policy or to report a Security issue, please contact us in one of the following ways:

Email : productsupport@Aivara Health.com

Telephone: +1 (330) 240-2047

Write to us at:

Aivara Health, Inc.
426 Arbor Circle, Youngstown Ohio- 44505

These Terms of Use were last updated on March 01, 2025