Security
Health data deserves stricter handling than ordinary app data. Here's the approach Stresfri Health is built around.
Template wording for this demo product, review with a legal advisor before launch.
Access control
Every record belongs to a single user, and row-level policies enforce that on the database itself, not just in the interface.
Server-side only secrets
API keys and model credentials never reach the browser. AI requests run through server functions.
Validation
All input is validated server-side before it's stored, including anything produced by an AI model.
Auditability
Security-relevant events are logged so unusual access can be investigated.
Reporting an issue
If you believe you've found a vulnerability, contact us through the support form and we'll respond quickly.
