Log in

Security

How we protect your health data.

Effective July 9, 2026 v2.0 — HIPAA-grade safeguards

The short version

01

HIPAA-grade safeguards

Kosei protects your health information with HIPAA-grade safeguards: encryption in transit and at rest, per-account access controls, audit logging, and permanent deletion within 30 days of account closure. Before you use Coach K, we ask for explicit consent and show you how AI features process your data.

Kosei implements administrative, technical, and physical safeguards aligned with the HIPAA Security Rule. We encrypt sensitive health fields at rest, offer multi-factor authentication, maintain tamper-evident audit logs, and contract with infrastructure providers under business associate agreements where health data is stored or processed.

Important: Kosei is a wellness technology company operated from New Jersey, not a healthcare provider or health plan. Kosei is not HIPAA-compliant and does not assert covered-entity status under HIPAA. The word grade describes our security posture — not a legal compliance certification.

02

Technical safeguards

  • Encryption in transit — TLS 1.2+ on every connection. HSTS enforced in production.
  • Encryption at rest — OAuth tokens and selected sensitive fields use AES-256-GCM application-level encryption. Database volumes are encrypted by the hosting provider.
  • Multi-factor authentication — TOTP-based MFA available on all accounts. Recommended for anyone storing lab results or wearable data.
  • Audit logging — Authentication events and PHI read paths (lab access, data export, coach conversations) are logged to a tamper-evident audit trail with no PHI in log payloads.
  • Account deletion — Deleting your account schedules permanent erasure within 30 days. You can export your data first at any time from Profile → Export.
  • Access controls — Production data access is restricted to authorized operators on a need-to-know basis.
03

Your data, our scores

Your raw health data remains yours. Kosei computes proprietary scores and indices for your account. Our scoring logic — including the Kosei Health Index, dimension weights, and organ-system models — is proprietary to Kosei.

Where scores incorporate documented public formulas (for example, PhenoAge-style biological age estimates), we document methodology in-app and cite primary literature. See our Terms of Service for the full split.

04

Subprocessors

These vendors process data on our behalf. We review their security posture regularly and pursue business associate agreements where health data is stored or processed.

VendorPurposeData handled
Fly.ioApplication hosting, compute, and encrypted volumesSession metadata, application logs (no PHI by policy)
NeonManaged Postgres databaseAll user health and account data at rest
xAI / GrokAI coaching, transcription, lab extractionAfter legal accept / product consent; context minimized
Upstash RedisCaching, rate limits, Coach K session stateEphemeral keys; PHI minimized in cached payloads
StripePayment processingBilling identity and payment methods for paid plans
Amazon S3Object storage for lab PDFs (when configured)Encrypted objects; access keyed to account
SentryError monitoringStack traces and request metadata (PHI scrubbed)
ResendTransactional email (verification, login alerts)Email address and message content only
05

Coach K and AI processing

Before your first Coach K conversation, we ask for explicit consent to send health context to xAI (Grok) for coaching responses. You can review what data is included in our Privacy Policy. We minimize the context sent with each request and log read access to your data.

06

Report a security issue

If you discover a vulnerability or have a security question, email longevitycorner@gmail.com with the subject line Security. We aim to acknowledge reports within 3 business days.

Please do not publicly disclose issues until we have had a chance to respond.