Security

How we protect your data.

Trophos stores the minimum needed to sync your health log. Everything else stays where it belongs: on your device.

Transport

All network traffic to and from Trophos is encrypted with TLS 1.3. We do not accept unencrypted connections.

Storage

Server-side data is encrypted at rest. Credentials are never stored in plain text; auth is handled by a hardened identity provider.

Health data synced from your phone

Health records synced from your phone are sealed on the device in an AES-256-GCM envelope, bound to your account, the key generation, the record type and its timestamps. Only the ciphertext is uploaded, so a database dump of that data yields ciphertext. Trophos can read it only if you turn on AI access, which escrows a copy of the key and is reversible. Reproductive and intimacy record types are never decrypted server-side regardless of that switch.

Data you create inside Trophos rides a different lane. It is encrypted in transit and at rest, minimized and pseudonymized, but the key is ours. We do not claim we cannot read it.

Access

Only a small set of on-call engineers can access production, and every access event is logged. We follow least-privilege access by default.

Responsible disclosure

Found something? Please email security@trophos.ai. We respond within one business day and credit reporters in release notes unless you prefer to stay anonymous.