Security at ClapDiet
The protections ClapDiet actually has, named specifically enough that you can hold us to them — and, at the end, the ones we do not claim.
What stands behind your account
Your health record is some of the most personal information you have. Here is what protects it, in terms you can check rather than adjectives you cannot.
1 year
Strict HTTPS policy
90 days
Access trail kept
0
Card details stored
How we keep you safe
Encrypted in transit
Every connection runs over HTTPS, and we send a strict-transport header covering every subdomain for a year — so your browser refuses a plain-HTTP connection to us even if something tries to force one.
Passwords are never stored
What we hold is a bcrypt hash: a one-way function slow enough that guessing through a stolen table is expensive rather than instant. Nobody here can read your password, including us.
Sign-in attempts lock out, progressively
Three failures lock the account for five minutes, five for fifteen, ten for an hour, twenty for a day. That turns thousands of guesses an hour into four.
Two-factor authentication
Optional TOTP — the rolling six-digit code from any authenticator app — with single-use backup codes that are hashed too, so the list we hold is not a list of usable codes.
Two independent access trails
The application records sign-ins, password changes and administrator actions; database triggers record changes to accounts, sessions, logins and lab panels underneath it. Both are kept 90 days.
Card details never reach us
Payments go through Stripe's own checkout page. There is no card number field anywhere in this product, which is the strongest form that promise can take.
Where your rights come from
Rights over your data are worth more than badges. These are implemented, not promised:
GDPR — download everything you have stored, correct anything, or delete your account and have the health record itself erased in one operation
HIPAA — ClapDiet is a consumer app, not a covered entity, so HIPAA does not bind us. Several of its Security Rule safeguards are in place anyway; our help centre lists which ones are not
HTTPS everywhere — with a one-year strict-transport policy and a content security policy that stops an injected script sending your data elsewhere
An access trail — including a record every time an administrator opens one person's profile or lab panel
What we do not claim
A security page is only worth reading if the absences are in it too. These are things this page used to claim and cannot support:
Encryption at rest — your data is encrypted in transit. The database itself is not separately encrypted, and saying otherwise would be the easiest sentence to write and the least true
A security certification — no SOC 2 report, no ISO 27001, and no independent audit to point you at
A bug bounty programme — there isn't one, and no penetration test has been published. Reports are still very welcome
Round-the-clock monitoring — nobody is watching a screen at 3am, and we publish no uptime figure because we do not measure one
Tips to stay safe
Here is what makes the most difference on your side:
- Use a password you use nowhere else
- Turn on two-factor authentication, and keep the backup codes somewhere other than your phone
- Do not share your password with anyone
- Log out when using a shared or public computer
- Treat any email asking for your password as fake — we never ask
- Keep your browser and devices updated
Found a Security Issue?
If you find a security problem, please tell us right away. We take all reports seriously and will work quickly to fix any issues.
Report a Security Issue