Security

Health data deserves stricter handling than ordinary app data. Here's the approach Stresfri Health is built around.

Template wording for this demo product, review with a legal advisor before launch.

Access control

Every record belongs to a single user, and row-level policies enforce that on the database itself, not just in the interface.

Server-side only secrets

API keys and model credentials never reach the browser. AI requests run through server functions.

Validation

All input is validated server-side before it's stored, including anything produced by an AI model.

Auditability

Security-relevant events are logged so unusual access can be investigated.

Reporting an issue

If you believe you've found a vulnerability, contact us through the support form and we'll respond quickly.