Technical details of how BodyFit secures our platform, infrastructure, and user data against unauthorised access and threats.
BodyFit runs on secure cloud infrastructure. Data in transit is encrypted using TLS. Access to infrastructure is restricted and authenticated. We apply security patches and updates promptly and monitor for threats. Our hosting provider maintains industry-standard physical and network security.
Our application follows secure coding practices: input validation, output encoding, access control on every request, and protection against common vulnerabilities (OWASP Top 10). Authentication uses secure tokens. Sensitive operations require re-authentication or admin role.
User data is stored securely with access controls. Sensitive data fields are protected. Row-level security ensures users can only access their own data. Admin access is logged and audited. Account deletion permanently removes personal data within 30 days.
We monitor our systems for security events, unusual access patterns, and potential threats. Alerts are triaged and investigated. Our audit trails support forensic analysis if needed. See our Audit & Assurance page.
Security Programme
BodyFit’s Security Programme protects user data and platform integrity through preventive, detective, and responsive security controls.
Vulnerability Reporting
Detailed guidance on reporting security vulnerabilities to BodyFit and what happens after you submit a report.
Responsible Disclosure
If you find a security vulnerability in BodyFit, we want to hear from you. Our responsible disclosure programme ensures reports are handled respectfully.
Security Certifications
BodyFit’s security certifications and compliance attestations demonstrate our commitment to protecting user data.