Security & data handling
What happens to a lab report you upload, who can see it, and what we do not claim. Every statement on this page describes how the service works today.
Your report file
A PDF or photo is read in memory and is not saved — not on our servers and not in the database. The text read from it, the values and the result are saved to your history so you can reopen them. You can delete any analysis, or your whole account, at any time.
Who processes medical data
- Vercel — runs our server, in Germany (Frankfurt). It handles the request and does not keep report contents.
- Supabase — our database, in Switzerland (Zurich). It stores your history and cases, encrypted at rest.
- Anthropic — the AI model that reads PDFs and writes summaries, in the United States. Under its commercial terms, API data is not used to train models and is deleted within 30 days.
- Resend — only when you send results by email yourself: the content of that email passes through it.
Payments go to Stripe, which receives your email and plan — never medical data. Invitation and notice emails contain no medical data.
Encryption
- In transit: HTTPS/TLS only, with HSTS preload. SSL Labs grade: A+.
- At rest: the database and its backups are encrypted with AES-256 by our database provider.
- Not end-to-end: to analyse a report, our server and the AI model have to read its text.
Who can see your data
Every record belongs to one account, and the database itself (Row Level Security) returns only that account's records. A colleague sees a shared case only after the workspace owner invites them. We do not sell data and show no ads.
Server logs
The production server does not write report text or values to its logs. Error logs record the type of error only.
Deleting your data
Delete a single analysis from History. Deleting your account removes your history, cases and notes, PDF branding and profile. If you own a team workspace, remove its members first.
What we do not claim
STRUCTA MED itself holds no security certification (ISO 27001, SOC 2) and has not yet had an external penetration test. Our database provider, Supabase, is SOC 2 Type 2 and ISO 27001 certified.
Found a vulnerability?
Write to support@structamed.com.