Security Policy

How we protect your data and keep your information safe

Last updated: March 21, 2026
Table of Contents
  1. Our Security Commitment
  2. Data Encryption
  3. Authentication & Access Control
  4. Infrastructure Security
  5. Financial Data Protection
  6. Application Security
  7. Data Retention & Deletion
  8. Third-Party Integrations
  9. Incident Response
  10. Vulnerability Disclosure
  11. Compliance & Standards
  12. Contact Us

1. Our Security Commitment

At Hardaway Labs LLC, security is foundational to everything we build. We understand that our users trust us with sensitive health, nutrition, and financial data, and we take that responsibility seriously. This policy outlines the technical and organizational measures we employ to protect your information across all HealthyOne products.

2. Data Encryption

In Transit

All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher (HTTPS). We enforce HTTPS-only connections and use HSTS headers to prevent downgrade attacks.

At Rest

Sensitive data stored in our databases is encrypted at rest. Financial credentials, including bank connection tokens, are encrypted using AES-256 encryption with securely managed keys that are never stored alongside the encrypted data.

Key Management

Encryption keys are stored separately from encrypted data and managed through environment-level secrets. Keys are rotated periodically and are never committed to source code repositories.

3. Authentication & Access Control

We implement multi-layered authentication and access controls to protect user accounts:

4. Infrastructure Security

Our infrastructure is hosted on industry-leading cloud platforms with robust security measures:

5. Financial Data Protection

For HealthyOne Finances, we implement additional security measures for financial data:

Important

HealthyOne Finances operates in read-only mode. We can never move money, initiate transactions, or make changes to your bank accounts. Your financial data is used solely for cash flow analysis and forecasting.

6. Application Security

7. Data Retention & Deletion

We retain your data only as long as necessary to provide our services:

8. Third-Party Integrations

We carefully vet all third-party services we integrate with. Our current partners include:

9. Incident Response

In the event of a security incident:

10. Vulnerability Disclosure

We welcome responsible security research. If you discover a security vulnerability in any HealthyOne product, please report it to us at security@hardawaylabs.com. We ask that you:

We commit to acknowledging receipt of vulnerability reports within 48 hours and providing status updates as we work toward a fix.

11. Compliance & Standards

Our security practices are guided by industry standards and frameworks:

12. Contact Us

If you have questions about our security practices or want to report a security concern:

Hardaway Labs LLC
Security: security@hardawaylabs.com
General: support@healthyoneapp.com
Website: healthyoneapp.com

We respond to all security inquiries within 48 hours.