Security
Your health data deserves the same care you put into your food choices.
Encryption
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Food photos are encrypted before storage and never used for model training without explicit opt-in.
Authentication
Passwords are hashed with bcrypt. We support passkeys and OAuth (Google, Apple). Sessions expire after 30 days of inactivity. Suspicious login attempts trigger email verification.
Infrastructure
We run on SOC 2 Type II certified cloud infrastructure. Database backups are encrypted and retained for 30 days. We do not run our own data centres.
SOC 2 controls
SOC 2 Type II audit in progress. We follow OWASP top-10 guidance, run automated dependency scanning, and perform periodic penetration tests.
Responsible disclosure
Found a vulnerability? Email security@wellsignal.co with details. We will acknowledge within 48 hours, keep you updated on our fix timeline, and credit researchers who follow responsible disclosure practices. We ask for 90 days before public disclosure.
Data minimisation
We collect only what is necessary for the service. Photos used for meal capture are processed for nutrition extraction then discarded from our AI pipeline within 24 hours unless you explicitly save them to your log.