Security & Privacy Architecture
Your health data stays exactly where it belongs
Protecht is built on a simple principle: your verified sexual health data lives on your device and nowhere else. Here's exactly how we protect it.
Protecht servers never see, touch, or store your health data — ever.
The Protecht On-Device PromiseHow it works
Three layers of protection
From the moment your results arrive to the second you share them, every step is designed to keep your data under your control.
-
01
On-Device Only Storage
Your STI results and vaccination records are downloaded directly to your iPhone and encrypted there. Protecht's servers are never in the data path.
- AES-256-GCM encryption via Apple CryptoKit
- Keys generated and stored in iOS Keychain
- Zero PHI transmitted to Protecht infrastructure
- Data persists only on your device — deleted when you uninstall
-
02
Secure Enclave Key Protection
Your encryption key is bound to Apple's Secure Enclave — a dedicated security chip that is physically isolated from the rest of the processor and inaccessible even to iOS itself.
- Keys never leave the Secure Enclave in plaintext
- Biometric authentication (Face ID / Touch ID) required to unlock
- Hardware-backed protection survives OS compromises
- Complies with FIPS 140-2 Level 2 standards
-
03
Time-Limited Secure Sharing
When you choose to share, a cryptographically signed, read-only snapshot is transmitted through an encrypted channel that auto-expires in 60 seconds — and can never be modified.
- 60-second access window, server-enforced expiry
- Read-only payload — structurally impossible to alter
- HTTPS-only transmission with certificate pinning
- Full audit log of every share event on your device
Data flow
From provider to your pocket — and nowhere else
Every hop in the data journey is authenticated, encrypted, and audited. Your health information flows to exactly one destination: your device.
Healthcare Provider
Epic-based systems like Kaiser, Sutter, UCSF, and Stanford — your verified results, connected via SMART on FHIR.
Apple Health on your iPhone
Your provider syncs results here once you've linked your records. This is the connection Protecht reads from — not a separate login.
Protecht, encrypted on-device
Data lands here and is encrypted immediately by CryptoKit. Your Secure Enclave holds the key.
Recipient's Device
A 60-second read-only snapshot, cryptographically signed. Expires automatically. Cannot be saved or forwarded.
What Protecht's servers handle
On-device architecture
Your iPhone is the vault
Most health apps store your data in the cloud, protected by their security. Protecht stores your data on your device, protected by Apple's most advanced hardware security — the Secure Enclave. Even if Protecht were to experience a data breach, there would be nothing to steal. Your health records never leave your device in unencrypted form.
Apple CryptoKit AES-256-GCM
AES-256-GCM authenticated encryption. Each record encrypted with a unique nonce, making brute-force attacks computationally infeasible.
iOS Keychain + Secure Enclave
Encryption keys are stored in the iOS Keychain, protected by the Secure Enclave. Keys are hardware-bound to your device and biometrics.
HTTPS-Only, Certificate-Pinned
All network communication uses TLS 1.3 with certificate pinning, preventing man-in-the-middle attacks even on compromised networks.
Sign In with Apple
Authentication is handled entirely by Apple — Protecht never sees your email address or password.
Sharing protocol
The 60-second share
When you choose to share your status, a carefully orchestrated 4-step protocol ensures the recipient sees exactly what you authorized — and nothing more.
-
01
You select & confirm
Choose which conditions to share. Face ID or Touch ID confirms your intent.
-
02
Payload encrypted & signed
A read-only snapshot is encrypted with a one-time key and cryptographically signed by your device.
-
03
Token delivered
Only a short-lived access token is routed through Protecht's server. Your health data is never stored there.
Token expires: 60 sec -
04
Recipient views — once
The verified snapshot is displayed. It cannot be saved, forwarded, or modified. The window closes after 60 seconds.
Healthcare integration
Provider-verified. Impossible to fake.
Protecht doesn't connect to your provider directly. You link your medical records in Apple Health, which handles the SMART on FHIR connection to your provider's system under the interoperability rules of the 21st Century Cures Act. Protecht then reads from Apple Health, with your permission.
The data originates from your provider's EHR system, arrives encrypted on your device, and is marked read-only. There is no mechanism for a user to alter a result — the architecture doesn't allow it.
Compliance
Built to meet the highest standards
Protecht's architecture was designed around compliance requirements — not retrofitted to meet them.
HIPAA Compliant
Full compliance with the Health Insurance Portability and Accountability Act. BAA-capable backend. Complete audit logging.
HealthKit Guidelines
Full compliance with Apple's HealthKit privacy requirements. No health data processed server-side without explicit user consent.
21st Century Cures Act
Data access built on USCDI standards and ONC interoperability rules. Patients' right to their own data, fully honored.
Full Audit Trails
Every data access, share event, and authentication attempt is logged with tamper-evident records stored locally on your device.
Ready to get started?
Privacy that doesn't ask you to compromise
Protecht gives you the ability to share your health status with complete confidence — because you control the data, the keys, and the clock.
Find Testing Near You