Security & Responsible Disclosure
Last updated: August 29, 2025
End-to-End Encryption
All data in transit uses HTTPS/TLS encryption. Industry-standard encryption at rest via our cloud provider.
Zero-Knowledge Auth
Sign in with Apple/Google. We don't store your email - only internal UUID and provider subject ID.
Minimal Data Footprint
Privacy-by-design architecture. User control with in-app delete and export functions.
Continuous Monitoring
Real-time security monitoring, rate limiting, and structured error handling with trace IDs.
🏗️ Architecture & Data Flow
High-Level Security Architecture
🛡️ Security Controls & Features
Authentication Security
Rate Limiting
Input Validation
Environment Separation
Backup & Recovery
Error Handling
🛡️ Data Protection & Privacy
What We Store
user_id (UUID) and provider sub only. No email collection for login.
Crash Diagnostics
Data Retention
User Control
🚨 Responsible Disclosure Policy
We welcome vulnerability reports. Please follow these guidelines to help keep users safe.
Include Details
Wait for Response
Safe-Harbor Guidelines
Allowed Testing
Out of Scope
📢 Incident Communication
If we determine that an incident materially affects users or legal obligations require it, we will provide notice via appropriate channels and include recommended user actions.
In-App Messages
Website Notices
Direct Email
Security Contact
1111B S Governors Ave STE 34726, Dover, DE 19904, United States
Security Email: support@babyshield.cureviax.com
Website: https://babyshield.cureviax.com
For privacy requests, see Privacy Policy and Data Deletion