Security Statement
Last updated: August 2026
Passwords are never stored in plain text. Each password is hashed using scrypt, a slow, salted hashing algorithm designed specifically to resist brute-force attacks, with a unique random salt per account.
All traffic to and from Vytal Path is encrypted in transit via HTTPS/TLS, including API requests, health data sync, and sign-in.
Login attempts are rate-limited: after 5 failed attempts, an account is locked out for 15 minutes to slow down password-guessing attacks. Optional two-factor authentication (a one-time code by SMS or email) can be turned on in My Account for extra protection.
A security activity log lets you review recent sign-ins and account changes yourself, from My Account.
Health data and account records are stored using Netlify's managed storage infrastructure (Netlify Blobs), which encrypts data at rest as part of its underlying platform.
Dependencies are checked against known-vulnerability databases; as of this writing, there are zero known vulnerabilities in the app's current dependencies.
No online service can guarantee absolute security, and by using Vytal Path you acknowledge that risk. If a breach occurs that's reasonably likely to affect your data, we'll notify affected users and take the steps required under applicable law, which may include the FTC Health Breach Notification Rule and state data-breach notification laws, depending on the circumstances.
Honest limitation: Vytal Path is not a hospital, doctor's office, or health plan, so HIPAA's rules for those entities don't directly apply here. Other laws aimed specifically at consumer health apps do apply, and our Privacy Policy and Incident Response Plan describe, in detail, how Vytal Path's consent, access, deletion, and breach-notification practices are built to meet the FTC Health Breach Notification Rule and the state health-privacy laws named there (Washington, Nevada, Connecticut, California, Colorado, Virginia, and Oregon). That work hasn't yet been the subject of a formal review by a licensed attorney, which is the one remaining step before treating it as a certified compliance program — the measures above and the linked policies reflect a genuine, current, good-faith effort, not a legal guarantee (e.g. no SOC 2 or similar third-party audit has been completed either). It's worth a conversation with legal counsel to get that final sign-off.
If you discover a security issue, please report it using the contact details under Contact Us so it can be addressed promptly.
