Security Center

How we protect your health data

All Security Measures Active

Encryption, rate limiting, input validation, and monitoring are all operational

Encryption

Transport Security
HTTPS/TLS encrypted
Security Headers
HSTS, CSP, X-Frame-Options
Cookie Security
HttpOnly, Secure, SameSite

Authentication

Login Methods
Google OAuth2 + Email/Password
Password Storage
bcrypt hashed (never plaintext)
Session Management
Auto-expiring secure tokens
Password Requirements
8+ chars, uppercase, lowercase, number

API Protection

Rate Limiting
Active on all AI & auth endpoints
Input Validation
All inputs sanitized against injection
CORS Policy
Restricted to authorized origins
Security Headers
CSP, HSTS, X-XSS-Protection enabled

Privacy & GDPR

Data Minimization
Only essential data collected
Right to Erasure
Delete all data with one click
Right to Portability
Export all data as JSON
No Ad Tracking
Zero advertising networks used

Monitoring

Failed Auth Logging
Brute-force attempts detected
Rate Limit Tracking
Abusive requests blocked & logged
Error Monitoring
Server errors tracked for investigation

Log in to access GDPR data management tools (export & delete your data)