Skip to content

Trust

Your health data, protected like it matters.

Security isn't a feature we bolted on — it's a constraint we design around. Here's what we actually do, described plainly rather than in certification language.

Encryption in transit and at rest

All traffic to Enaro runs over TLS. Your reports and results are encrypted at rest in our database and file storage.

Per-account data isolation

Database-level row-level security ensures your records are only ever queryable by your own authenticated session — not just filtered in application code.

You own your data

Export your data or delete your account at any time from Settings. Deleted data is retained for 30 days to protect against accidental deletion, then permanently removed.

Never sold

We do not sell your personal health information to third parties, ever.

Least-privilege processing

Report processing (OCR and AI extraction) runs through dedicated, access-scoped service credentials — not your session — and only to structure your report.

Responsible disclosure

Found a security issue? We want to know — email us and we'll respond promptly.

What we don't claim

Honest, not overstated

Enaro does not currently hold formal certifications such as SOC 2, ISO 27001, or HIPAA compliance attestation. We are not going to claim them here until they are actually earned and verifiable — see our Data & Privacy page for our current, honest position on data protection frameworks.

Automated backups are not yet enabled on our current infrastructure tier — this is a hard gate we've set for ourselves before onboarding real users beyond our founding team, not a soft target.

Report a security concern to hello@enaro.care.