Security
How we protect your health data.
The short version
- Kosei uses HIPAA-grade safeguards — encryption, MFA, access controls, and audit logging.
- Kosei is not HIPAA-compliant and is not a healthcare provider, health plan, or covered entity.
- Your raw health data is yours. Our scoring algorithms are proprietary; published formulas are documented in-app.
- Account deletion schedules permanent erasure within 30 days.
HIPAA-grade safeguards
Kosei protects your health information with HIPAA-grade safeguards: encryption in transit and at rest, per-account access controls, audit logging, and permanent deletion within 30 days of account closure. Before you use Coach K, we ask for explicit consent and show you how AI features process your data.
Kosei implements administrative, technical, and physical safeguards aligned with the HIPAA Security Rule. We encrypt sensitive health fields at rest, offer multi-factor authentication, maintain tamper-evident audit logs, and contract with infrastructure providers under business associate agreements where health data is stored or processed.
Important: Kosei is a wellness technology company operated from New Jersey, not a healthcare provider or health plan. Kosei is not HIPAA-compliant and does not assert covered-entity status under HIPAA. The word grade describes our security posture — not a legal compliance certification.
Technical safeguards
- Encryption in transit — TLS 1.2+ on every connection. HSTS enforced in production.
- Encryption at rest — OAuth tokens and selected sensitive fields use AES-256-GCM application-level encryption. Database volumes are encrypted by the hosting provider.
- Multi-factor authentication — TOTP-based MFA available on all accounts. Recommended for anyone storing lab results or wearable data.
- Audit logging — Authentication events and PHI read paths (lab access, data export, coach conversations) are logged to a tamper-evident audit trail with no PHI in log payloads.
- Account deletion — Deleting your account schedules permanent erasure within 30 days. You can export your data first at any time from Profile → Export.
- Access controls — Production data access is restricted to authorized operators on a need-to-know basis.
Your data, our scores
Your raw health data remains yours. Kosei computes proprietary scores and indices for your account. Our scoring logic — including the Kosei Health Index, dimension weights, and organ-system models — is proprietary to Kosei.
Where scores incorporate documented public formulas (for example, PhenoAge-style biological age estimates), we document methodology in-app and cite primary literature. See our Terms of Service for the full split.
Subprocessors
These vendors process data on our behalf. We review their security posture regularly and pursue business associate agreements where health data is stored or processed.
| Vendor | Purpose | Data handled |
|---|---|---|
| Fly.io | Application hosting, compute, and encrypted volumes | Session metadata, application logs (no PHI by policy) |
| Neon | Managed Postgres database | All user health and account data at rest |
| xAI / Grok | AI coaching, transcription, lab extraction | After legal accept / product consent; context minimized |
| Upstash Redis | Caching, rate limits, Coach K session state | Ephemeral keys; PHI minimized in cached payloads |
| Stripe | Payment processing | Billing identity and payment methods for paid plans |
| Amazon S3 | Object storage for lab PDFs (when configured) | Encrypted objects; access keyed to account |
| Sentry | Error monitoring | Stack traces and request metadata (PHI scrubbed) |
| Resend | Transactional email (verification, login alerts) | Email address and message content only |
Coach K and AI processing
Before your first Coach K conversation, we ask for explicit consent to send health context to xAI (Grok) for coaching responses. You can review what data is included in our Privacy Policy. We minimize the context sent with each request and log read access to your data.
Report a security issue
If you discover a vulnerability or have a security question, email longevitycorner@gmail.com with the subject line Security. We aim to acknowledge reports within 3 business days.
Please do not publicly disclose issues until we have had a chance to respond.