SECURECORDSSECURECORDS

Security

Encrypted before it leaves your device.

SECURECORDS is built so that your health records are readable only by you. Here's exactly how — in plain language first, then the technical details.

In plain language

Your device does the encrypting

When you save a result, your browser encrypts it before sending it. What reaches us is scrambled data.

Only you hold the key

Your data key is locked with your password and, separately, with a recovery key. We never receive either.

Our servers can't read it

We store ciphertext. Without your key it's unreadable — to our team, our hosting provider, or anyone who breaks in.

What happens, step by step

  1. You create an account

    Your browser generates a random 256-bit data key. It locks (encrypts) that key twice: once with a key derived from your password, and once with a separate recovery key that's shown to you once. Only the locked copies are sent to us.

  2. You save a result

    Each record — values, dates, notes, which test it is — is encrypted with your data key and sealed to that record, so it can't be swapped or altered without detection. We receive only the encrypted result.

  3. You sign in on another device

    Your password is turned into two separate keys on your device: one proves who you are to us, the other unlocks your data key. Only the first is ever sent, so signing in never reveals the key that decrypts your records.

  4. You forget your password

    Your recovery key unlocks your data key instead. You choose a new password and get a fresh recovery key; the old one stops working.

  5. You close the tab or step away

    The decryption key lives only in the open page. Reloading, signing out or the automatic inactivity lock clears it.

Technical details

Record encryptionAES-256-GCM via the browser's built-in Web Crypto API. A random 96-bit IV per record; associated data binds each ciphertext to its record type and ID.
Password key derivationArgon2id (64 MiB memory, 3 passes) with a random per-user salt, run on your device.
Separate login & encryption keysHKDF-SHA256 derives an authentication key and a key-encryption key from the Argon2id output. Only the authentication key is sent; the server stores a salted PBKDF2-SHA256 hash of it.
Data keyA random 256-bit key per user, wrapped with AES-256-GCM by the password-derived key and, separately, by the recovery key. Held in memory as a non-extractable key while unlocked.
Passkey unlock (optional)Per device. After your device verifies you (Face ID, fingerprint, Windows Hello or PIN), the passkey gives the browser a secret through the WebAuthn PRF extension. HKDF turns it into a key that wraps the same data key with AES-256-GCM, bound to that passkey. The secret never leaves your device; we store only the wrapped key. Passkeys unlock an existing session only — signing in still needs your password.
Recovery key256 bits from a cryptographic random generator, with a built-in checksum to catch typos. Replaced after every use.
What's encryptedEvery value, date, time and note; which markers you track; custom biomarker definitions; life events; your name, date of birth, sex, height and preferences; family profiles' details and which records belong to each profile.
What isn'tYour email address; the number and size of stored records and when they were saved; whether each tracked marker is built-in or custom (not which one); how many profiles the account has (not who they are or which records are theirs); your plan and billing status; and standard request logs, such as IP addresses, used for security. Payments are processed by Stripe — card details never reach our servers.
LibrariesCryptography uses the browser's Web Crypto API. The Argon2 and PDF libraries are served from our own site. The only third-party script anywhere is Cloudflare Turnstile (a bot check), on two pages: the first sign-up step, where you enter your email, and the contact form. Both are separate pages that open and close with a full page load: your password is typed, and your keys are created, only on pages where no third-party script has run.

Other protections

  • Automatic lock after inactivity (you choose the timeout)
  • Optional passkey unlock (Face ID, fingerprint, PIN), set up per device, without weakening encryption
  • Changing your password signs out your other devices
  • Sign-in attempts are rate-limited against guessing
  • Sign-ups are protected against bots: a bot check, email confirmation and checks for fake or disposable email domains
  • Unknown email addresses aren't revealed at sign-in
  • No advertising, analytics or third-party trackers
  • PDF reports are built on your device; nothing is uploaded
  • Secure, same-site-only session cookies
  • Account deletion removes every record permanently

Honest limitations

No system is perfect, and we'd rather you understand the trade-offs than be surprised by them.

We can't recover a lost password and recovery key

That's the other side of us never holding your key. Keep your recovery key somewhere safe and offline.

Your device matters

Your records are decrypted on the device you use. If that device is compromised — for example by malware — your data could be exposed there. Keep it updated and locked.

You're trusting the app we serve

Like every web app, SECURECORDS runs code delivered by our server. Encryption protects your stored data; it depends on that code being what we say it is.

Some information isn't encrypted

Your email address, your plan and billing status, and basic account metadata (such as how many records and profiles you have) are needed to run the service.

Exports are ordinary files

PDF reports and downloads are created on your device and are not encrypted. Anyone with a copy can read it.

Encryption protects secrecy, not availability

Encryption stops us reading your data, but you still rely on us to store it. Download a copy of your records from time to time.

Reporting a security issue

If you believe you've found a vulnerability, please tell us through our contact form — choose "Security or privacy concern". Please don't include anyone's health information in your report.

Privacy by design, in every plan — including Free.

Start free
An unhandled error has occurred. Reload 🗙