I HealthLens

Security & Sub-processors

A summary of how we keep your data safe — what we encrypt, who we trust to operate parts of the service, how we respond to incidents, and how to disclose a vulnerability to us responsibly.

Effective date: 9 May 2026 · Last updated: 9 May 2026

1. Architecture at a glance

2. Encryption

3. Access control

4. Sub-processors

We use the following sub-processors to deliver the app. Each has signed a data-processing agreement (DPA) consistent with the GDPR / UK GDPR / DPDP Act, and where relevant has agreed to the European Commission's Standard Contractual Clauses (2021).

Sub-processorFunctionRegionTrust resources
Supabase, Inc. Auth, Postgres, Storage, Edge Functions Configured Supabase region supabase.com/security
Microsoft Corporation (Azure OpenAI Service) LLM inference Configured Azure region Azure OpenAI data privacy
Google LLC Sign-In, on-device ML Kit, Firebase Hosting (this site), optional FCM Google global cloud.google.com/security
Apple Inc. Sign in with Apple Apple global apple.com/legal/privacy
Translated S.r.l. (MyMemory) Machine translation EU MyMemory privacy

We will give notice before adding a new sub-processor that processes a meaningful new category of data, and we will offer EEA / UK / India users a way to object before the change takes effect.

5. Vulnerability disclosure

We welcome responsible disclosure of security issues. To report a vulnerability:

  1. Email contact@fcappstudio.tech with subject line [Security].
  2. Include a clear description, reproduction steps, and any proof of concept. If the issue is sensitive, request our PGP key first.
  3. Give us a reasonable time to investigate and remediate before any public disclosure (we aim for 90 days; sooner if the fix is straightforward).
  4. Do not access or modify other users' data, do not run automated scanners that degrade availability, and do not publicly disclose the issue while we work on a fix.

We will acknowledge receipt within 72 hours and provide a remediation timeline within 7 days. We do not currently run a paid bug-bounty programme but we will publicly credit researchers who agree.

6. Incident response

Our incident-response procedure is summarised below.

  1. Detect & triage. Logs, alerts, or a third-party report identify a possible incident.
  2. Contain. Compromised credentials are rotated immediately. The affected component is isolated.
  3. Assess. We determine which records were affected, the categories of data involved, and the likely impact.
  4. Notify. If the incident is likely to result in a risk to your rights and freedoms, we notify the relevant supervisory authority and you, as required by law (within 72 hours under GDPR; without undue delay under the DPDP Act).
  5. Remediate. We deploy the fix and verify it.
  6. Review. We carry out a blameless post-mortem and update our controls.

7. Secure-by-default mobile build

8. Out of scope

The following are outside our security boundary:

9. Contact

For security questions, email contact@fcappstudio.tech with subject [Security].