Security Center
How we protect your health data
All Security Measures Active
Encryption, rate limiting, input validation, and monitoring are all operational
Encryption
Transport Security
HTTPS/TLS encrypted
Security Headers
HSTS, CSP, X-Frame-Options
Cookie Security
HttpOnly, Secure, SameSite
Authentication
Login Methods
Google OAuth2 + Email/Password
Password Storage
bcrypt hashed (never plaintext)
Session Management
Auto-expiring secure tokens
Password Requirements
8+ chars, uppercase, lowercase, number
API Protection
Rate Limiting
Active on all AI & auth endpoints
Input Validation
All inputs sanitized against injection
CORS Policy
Restricted to authorized origins
Security Headers
CSP, HSTS, X-XSS-Protection enabled
Privacy & GDPR
Data Minimization
Only essential data collected
Right to Erasure
Delete all data with one click
Right to Portability
Export all data as JSON
No Ad Tracking
Zero advertising networks used
Monitoring
Failed Auth Logging
Brute-force attempts detected
Rate Limit Tracking
Abusive requests blocked & logged
Error Monitoring
Server errors tracked for investigation
Log in to access GDPR data management tools (export & delete your data)