BodyFit's security programme — how we protect your data, manage vulnerabilities, and respond to incidents. Security is foundational to everything we build.
BodyFit is built on a secure cloud infrastructure with encryption in transit (TLS) and at rest. We follow least-privilege access principles, with role-based access controls and audit logging for all administrative actions. Our architecture separates user data from authentication credentials, and sensitive data such as OAuth tokens are encrypted before storage. We conduct regular security reviews of our codebase, dependencies, and infrastructure configuration. See our System Security and Trust Centre pages for more detail on our architecture and controls.
Access to user data is restricted to authorised personnel with a legitimate need, and all access is logged and reviewable. Administrators can only access user data through audited administrative functions — there is no unrestricted database access. We conduct access reviews on a regular cadence and revoke access immediately when personnel change roles or leave. Users can see and manage their own data through the app, including exporting and deleting their account. See our Privacy Governance and GDPR Rights pages for how access rights work for users.
We maintain a vulnerability management programme that includes dependency scanning, code review, and a responsible disclosure process for external security researchers. Our Vulnerability Reporting page provides clear instructions for reporting security issues and describes our response timelines. We triage all reports promptly, acknowledge valid findings, and fix confirmed vulnerabilities according to severity. We recognise researchers who help us improve security. See our Security Certifications page for our compliance alignment and our Responsible Disclosure policy.
Our incident response plan defines how we detect, assess, contain, eradicate, and recover from security incidents. We monitor for anomalies, maintain alerting infrastructure, and conduct post-incident reviews to learn and improve. If an incident affects user data, we notify affected users as required by law and where there is meaningful risk of harm. We publish incident summaries in our Transparency Reports. See our Business Continuity and Disaster Recovery pages for how we maintain service during disruptions, and our Risk Management page for our broader risk framework.
System Security
Technical details of how BodyFit secures our platform, infrastructure, and user data against unauthorised access and threats.
Responsible Disclosure
If you find a security vulnerability in BodyFit, we want to hear from you. Our responsible disclosure programme ensures reports are handled respectfully.
Vulnerability Reporting
Detailed guidance on reporting security vulnerabilities to BodyFit and what happens after you submit a report.
Business Continuity
BodyFit’s Business Continuity plan ensures we can continue operating and serving users during disruptions.