BodyFit’s security certifications and compliance attestations demonstrate our commitment to protecting user data.
BodyFit is in beta (RC35) and is building toward formal security certifications. Our infrastructure runs on providers with industry-standard certifications (ISO 27001, SOC 2). We are working toward our own certifications as we scale beyond beta.
We follow security best practices aligned with recognised frameworks: secure coding standards, access controls, encryption, vulnerability management, and incident response. Our Security Programme documents these controls. We conduct internal security reviews.
Our roadmap includes pursuing ISO 27001 and SOC 2 Type II certifications as we grow. We will update this page as certifications are achieved. Until then, our Security Programme, Trust Centre, and Transparency Reports provide visibility into our practices.
We use cloud infrastructure and services from providers with their own security certifications. We evaluate vendors’ security posture before engagement and require appropriate data processing agreements. See our Compliance page for regulatory standing.
Security Programme
BodyFit’s Security Programme protects user data and platform integrity through preventive, detective, and responsive security controls.
System Security
Technical details of how BodyFit secures our platform, infrastructure, and user data against unauthorised access and threats.
Compliance
BodyFit operates in compliance with applicable UK and international regulations governing data protection, AI, and digital health.
Trust Centre
The BodyFit Trust Centre is your central resource for understanding our security, privacy, and AI practices — all in one place.