Security and Data Protection

1.1. Security is a central pillar of Softdiet. The entire platform — including the web application and mobile applications — was developed based on international security practices and secure development principles.

1.2. Softdiet follows the recommendations of OWASP (Open Web Application Security Project), applying its guidelines to prevent common vulnerabilities in web and mobile applications and to protect sensitive clinical data. The implemented measures include:

  • Encrypted communication (HTTPS/TLS) for all data transmitted between devices and servers.
  • Full data encryption at rest, ensuring that not even server administrators can access information in readable format.
  • Zero‑knowledge access model, where no password or sensitive credential is stored in plain text or accessible to third parties.
  • Strict access isolation, where only one person has access to the infrastructure, but cannot access patient data due to encryption.
  • Secure credential management, with all passwords stored in an encrypted vault (KeePass) requiring device decryption and multi‑factor authentication.
  • Real‑time login alerts, ensuring that any access attempt generates an immediate notification on the professional’s mobile phone.
  • Secure authentication and session management, with protection against session hijacking.
  • Input validation and sanitization, preventing SQL Injection, XSS and other injection attacks.
  • Role‑based access control, ensuring that professionals and patients only access data intended for their profile.
  • APIs developed following OWASP API Security Top 10 principles.
  • Frequent encrypted backups, currently performed hourly, with controlled restoration procedures.
  • Continuous infrastructure monitoring, including logging and anomaly detection.
  • Secure development lifecycle, with code review and vulnerability prevention practices.
  • Principle of least privilege applied to internal systems and external services.

1.3. Softdiet’s infrastructure follows strict policies for backups, access control and secure server management, ensuring the integrity, availability and confidentiality of all clinical information.

1.4. Softdiet is committed to offering a reliable, secure platform aligned with modern data protection standards, allowing healthcare professionals and patients to use a system built with responsibility and technical rigor.

Transparency Policy and Technical Visits

2.1. Softdiet maintains an active commitment to transparency. Whenever requested by institutions, partners or healthcare professionals, it is possible to schedule a technical visit to learn about our processes, security practices and operational infrastructure. These visits are conducted in a controlled environment, ensuring data protection and compliance with privacy standards, allowing each visitor to personally verify the rigor and responsibility with which Softdiet is developed and maintained.