governance

Security Programme

BodyFit's security programme — how we protect your data, manage vulnerabilities, and respond to incidents. Security is foundational to everything we build.

v1.0 Updated 4 Aug 2026

Security Architecture

BodyFit is built on a secure cloud infrastructure with encryption in transit (TLS) and at rest. We follow least-privilege access principles, with role-based access controls and audit logging for all administrative actions. Our architecture separates user data from authentication credentials, and sensitive data such as OAuth tokens are encrypted before storage. We conduct regular security reviews of our codebase, dependencies, and infrastructure configuration. See our System Security and Trust Centre pages for more detail on our architecture and controls.

Access Control

Access to user data is restricted to authorised personnel with a legitimate need, and all access is logged and reviewable. Administrators can only access user data through audited administrative functions — there is no unrestricted database access. We conduct access reviews on a regular cadence and revoke access immediately when personnel change roles or leave. Users can see and manage their own data through the app, including exporting and deleting their account. See our Privacy Governance and GDPR Rights pages for how access rights work for users.

Vulnerability Management

We maintain a vulnerability management programme that includes dependency scanning, code review, and a responsible disclosure process for external security researchers. Our Vulnerability Reporting page provides clear instructions for reporting security issues and describes our response timelines. We triage all reports promptly, acknowledge valid findings, and fix confirmed vulnerabilities according to severity. We recognise researchers who help us improve security. See our Security Certifications page for our compliance alignment and our Responsible Disclosure policy.

Incident Response

Our incident response plan defines how we detect, assess, contain, eradicate, and recover from security incidents. We monitor for anomalies, maintain alerting infrastructure, and conduct post-incident reviews to learn and improve. If an incident affects user data, we notify affected users as required by law and where there is meaningful risk of harm. We publish incident summaries in our Transparency Reports. See our Business Continuity and Disaster Recovery pages for how we maintain service during disruptions, and our Risk Management page for our broader risk framework.

Related Pages