Security at VitaFlow Care

Protecting Your Data is Our Top Priority

Security Certifications & Compliance

1.1 Compliance Standards

GDPR Compliant

Full compliance with EU General Data Protection Regulation.

SOC 2 Type 2 Certified

Annual independent audit of security controls.

ISO 27001 Aligned

Information Security Management System (ISMS).

HIPAA-Ready Architecture

Infrastructure capable of supporting HIPAA requirements (US market).

PCI-DSS Compliant

Payment processing through certified provider (Polar).

Data Encryption

2.1 Encryption in Transit

All data transmitted between your browser and our servers is encrypted using TLS 1.3.

2.2 Encryption at Rest

All data is encrypted at rest in our databases using AES-256.

2.3 Key Management

Master keys are stored in Hardware Security Modules (HSM) with regular key rotation.

Access Control & Authentication

3.1 User Authentication

Multi-Factor Authentication (MFA), strong password requirements, and secure session management are enforced.

3.2 Authorization & Access Control

We use Role-Based Access Control (RBAC) and database-level security to ensure users can only access their own data.

Infrastructure Security

4.1 Network Security

We employ firewall protection, DDoS protection, and intrusion detection systems.

4.2 Server Security

Our servers use hardened operating systems with automatic security updates and regular vulnerability scanning.

Application Security

5.1 Secure Development Practices

We follow security by design principles, including mandatory code reviews and threat modeling.

5.2 Common Vulnerability Protection

We protect against common vulnerabilities such as SQL Injection, XSS, and CSRF.

Incident Response & Business Continuity

7.1 Security Incident Response Plan

We have a comprehensive incident response plan to detect, contain, and respond to security incidents.

7.3 Business Continuity & Disaster Recovery

We have automated daily backups, continuous replication, and a disaster recovery plan with a 4-hour Recovery Time Objective (RTO).

Employee Security & Training

9.1 Personnel Security

All employees undergo background checks and are required to sign confidentiality agreements.

9.2 Security Awareness Training

We provide mandatory security training, including phishing simulations and secure coding practices.

Frequently Asked Questions

Where is my data stored?

All data is stored exclusively on EU servers in Germany.

Can VitaFlow Care employees see my health data?

No. Health data is encrypted and only accessible to the practitioner and client involved.

What happens if there's a data breach?

We will notify affected users within 24 hours and the Belgian Data Protection Authority within 72 hours if required by GDPR.