Company

Trust & security

Plain answers, dated and versioned. Where something is not done yet, we say so. Every statement on this page has a matching piece of evidence in our repository.

Version 1.0 · Last updated 2026-09-15

Your report stays on your device

Extracted values are stored in your browser, not on our servers. The file itself is only passed through for reading.

Account data in the EU

E-mail, password hash, sex and birth year live in a database in Western Europe. Nothing else is required.

Encrypted everywhere

TLS 1.3 in transit, encryption at rest, passwords hashed with PBKDF2, one-time codes and session tokens stored only as hashes.

Delete everything, immediately

Account deletion removes the account, sessions and entitlements at once and anonymises the security log.

What we process, where and for how long

DataWhereWhyRetention
Report file (PDF or photo)In transit only: our AI worker (Cloudflare) and Anthropic, for reading the valuesTo extract markers, units and ranges from the reportNot stored by Blood Lab 360. Anthropic keeps API inputs up to 30 days for abuse monitoring and does not train on them.in place
Extracted values, age band, sexYour browser (local storage); sent to the AI worker only when you ask for an explanation or chatExplanations and answers for your age and sexNever with your name or date of birth. Not stored on our servers.in place
Account: e-mail, password, sex, birth year, contextsCloudflare D1 database, Western Europe regionLogin on every device, correct reference rangesUntil you delete the account. Password only as a salted PBKDF2-SHA256 hash.in place
Security logSame databaseRate limits, abuse detection, incident reconstructionEvent type and a daily hash of the IP address, never the raw IP or browser fingerprint. Rows are anonymised when you delete the account.in place
Anonymous usage eventsCloudflare D1To learn which explanations people needNo user or session identifier, no IP, no free text: events cannot be linked to a person.in place
Website analyticsCloudflare Web AnalyticsPage views and speedNo cookies, no cross-site tracking, no advertising identifiers.in place
Messages you send us (feedback, business enquiry)Cloudflare KV and the info@ mailboxTo answer youUntil handled; business enquiries until the offer is closed.in place

Sub-processors

We keep the list short. Each provider is bound by a data processing agreement and, where data leaves the EU, by standard contractual clauses.

ProviderPurposeLocationNotes
Cloudflare, Inc.Website hosting, application workers, database (D1), key-value store, DNS, web analyticsGlobal edge; database placed in Western EuropeDPA with SCCs; encryption at rest and in transitin place
Anthropic, PBCAI model (Claude) for reading reports and writing explanationsUnited StatesDPA with SCCs; no training on API data; inputs kept up to 30 days for abuse monitoringin place
Resend, Inc.Transactional e-mail (login codes)EU region (Ireland)Only your e-mail address and the codein place
Webtasy d.o.o. (controlpanel.si)Company mailbox info@ and domain registrationSloveniaE-mails you send to usin place
Google LLCOnly if you choose “Continue with Google”United StatesWe receive your verified e-mail and a stable Google ID, nothing elsein place
Payment providerPremium purchasesNot active yet. Card data will never touch our servers.not yet

Encryption and application security

  • in placeTLS 1.3 on every request, HTTP Strict Transport Security enabled.
  • in placeData at rest is encrypted by Cloudflare (D1, KV, Pages).
  • in placePasswords: PBKDF2-SHA256, 100 000 iterations, 16-byte random salt, plus a server-side secret for one-time codes.
  • in placeOne-time codes: 6 digits, 10 minutes, 5 attempts, at most 5 per day; session tokens stored only as SHA-256.
  • in placeContent Security Policy and full set of security headers on the website and the application; Mozilla Observatory B+ (80/100) on 15 Sep 2026.
  • in placeRate limits on the AI service: 20 requests per minute and 60 per day per address, 1 500 per day in total; bot check (Turnstile) ready to switch on.
  • in placePDF parsing runs in your browser with a self-hosted library; no third-party script can read your report.
  • in placeSecrets live only in Cloudflare’s secret store, never in code; every commit is scanned.

Access, backups and continuity

  • in placeAdministrative access is limited to the company’s founders; source code is in private repositories with automated tests on every change.
  • in placeDatabase point-in-time recovery for the last 30 days (Cloudflare D1 Time Travel).
  • in placeEvery website and application release is kept; rollback to a previous release takes one command.
  • in progressNightly off-site database exports to separate storage.
  • in progressHardware-key two-factor authentication on all administrator accounts.

Monitoring and incidents

  • in placeIf a breach affects your data, we notify you and the Slovenian Information Commissioner within 72 hours, with what happened and what we did.
  • in placeTraffic and errors are visible in Cloudflare analytics; releases are verified with an automated live check (46 tests) before and after deployment.
  • in progressAutomated uptime monitoring with alerts and a public status page.

How the AI is used (EU AI Act, Article 50)

  • in placeExplanations and the chat are generated by an AI model (Claude by Anthropic) and are labelled as such wherever they appear.
  • in placeThe model is constrained to our knowledge base: reference ranges, marker facts and sources are written and reviewed by us; the model may not add medical claims of its own.
  • in placeEvery reference range shows its source. Values are rated by a deterministic engine, not by the language model.
  • in placeBlood Lab 360 does not diagnose, treat or replace a doctor. When a value needs a doctor, we say so clearly.
  • in progressMedical device status: Blood Lab 360 is offered as an educational tool. A formal regulatory classification review is scheduled before paid features launch.

Your rights

  • in placeAccess and export: write to info@bloodlab360.com and you receive your account data within 30 days; an in-app export button is coming.
  • in placeCorrection: sex, birth year and contexts can be changed in your profile at any time.
  • in placeDeletion: immediate and complete on the server (account, sessions, entitlements); your report values stay only on your device and you can clear them there.
  • in placeComplaint: Informacijski pooblaščenec Republike Slovenije, Dunajska 22, 1000 Ljubljana, gp.ip@ip-rs.si.

Reporting a security issue

  • in placeWrite to info@bloodlab360.com (details in /.well-known/security.txt). We acknowledge within 72 hours and keep you informed until the fix is live.
  • in placeGood-faith research that avoids privacy violations, data destruction and service disruption will not be pursued legally. There is no paid bounty programme.

What we do not have yet

We would rather list it than let you assume it.

  • not yetSOC 2 or ISO 27001 certification.
  • not yetIndependent penetration test (planned before paid launch).
  • in progressSigned-off data protection impact assessment (DPIA) for health data (in progress).
  • in progressAutomated uptime monitoring and public status page (in progress).
  • in progressNightly off-site backups (in progress).
  • not yetAutomatic purge of the security log after 12 months.
  • not yetPayments, invoicing and Premium (not live).
  • in progressIn-app buttons for data export and account deletion (today by e-mail).

Changes

  • 1.02026-09-15 · First publication.

Questions about this page: info@bloodlab360.com · security.txt · Privacy

Upload your report — free →