Security at VitaFlow Care
Protecting Your Data is Our Top Priority
Security Certifications & Compliance
1.1 Compliance Standards
GDPR Compliant
Full compliance with EU General Data Protection Regulation.
SOC 2 Type 2 Certified
Annual independent audit of security controls.
ISO 27001 Aligned
Information Security Management System (ISMS).
HIPAA-Ready Architecture
Infrastructure capable of supporting HIPAA requirements (US market).
PCI-DSS Compliant
Payment processing through certified provider (Polar).
Data Encryption
2.1 Encryption in Transit
All data transmitted between your browser and our servers is encrypted using TLS 1.3.
2.2 Encryption at Rest
All data is encrypted at rest in our databases using AES-256.
2.3 Key Management
Master keys are stored in Hardware Security Modules (HSM) with regular key rotation.
Access Control & Authentication
3.1 User Authentication
Multi-Factor Authentication (MFA), strong password requirements, and secure session management are enforced.
3.2 Authorization & Access Control
We use Role-Based Access Control (RBAC) and database-level security to ensure users can only access their own data.
Infrastructure Security
4.1 Network Security
We employ firewall protection, DDoS protection, and intrusion detection systems.
4.2 Server Security
Our servers use hardened operating systems with automatic security updates and regular vulnerability scanning.
Application Security
5.1 Secure Development Practices
We follow security by design principles, including mandatory code reviews and threat modeling.
5.2 Common Vulnerability Protection
We protect against common vulnerabilities such as SQL Injection, XSS, and CSRF.
Incident Response & Business Continuity
7.1 Security Incident Response Plan
We have a comprehensive incident response plan to detect, contain, and respond to security incidents.
7.3 Business Continuity & Disaster Recovery
We have automated daily backups, continuous replication, and a disaster recovery plan with a 4-hour Recovery Time Objective (RTO).
Employee Security & Training
9.1 Personnel Security
All employees undergo background checks and are required to sign confidentiality agreements.
9.2 Security Awareness Training
We provide mandatory security training, including phishing simulations and secure coding practices.
Frequently Asked Questions
Where is my data stored?
All data is stored exclusively on EU servers in Germany.
Can VitaFlow Care employees see my health data?
No. Health data is encrypted and only accessible to the practitioner and client involved.
What happens if there's a data breach?
We will notify affected users within 24 hours and the Belgian Data Protection Authority within 72 hours if required by GDPR.