Security
How we protect your health data.
The short version
- Kosei is a paid consumer wellness membership, not a clinic, health plan, or HIPAA covered entity.
- We encrypt selected sensitive fields, require a signed-in session for health APIs, and offer MFA. We are not HIPAA-compliant and we do not use HIPAA business associate agreements for this product.
- Coach K sends relevant health context to xAI (Grok) so it can answer you. We ask before the first conversation.
- Account deletion schedules permanent erasure within 30 days. Export anytime from Profile.
What Kosei is (and is not)
Kosei is a paid precision-health membership operated from New Jersey. You buy Kosei for yourself. We are not a healthcare provider, not a health plan, and not a HIPAA covered entity. We do not process health data on behalf of a clinic, employer, or insurer.
HIPAA business associate agreements (BAAs) do not apply to this product. A BAA is a HIPAA contract used when a vendor handles protected health information for a covered entity. That is not our model. If we ever offered Kosei to a clinic, employer, or health plan, that would be a separate program with different contracts. We refuse those deals until that program exists.
Kosei is not HIPAA-compliant and does not claim covered-entity or business-associate status. The controls below are what we actually run. We do not market a HIPAA certification we do not have.
Technical controls
- Encryption in transit — TLS 1.2+ on every connection. HSTS in production.
- Encryption at rest (application) — AES-256-GCM for OAuth tokens, Coach K messages, voice transcripts, lab names and values, lab PDF objects, and Coach K cache payloads. Production refuses to store those fields if the encryption key is missing.
- Encryption at rest (infrastructure) — Neon and Fly encrypt volumes. Wearable metrics, meals, workouts, and scores are protected by access control and vendor disk encryption, not a second application-layer cipher.
- Access — Health APIs require an authenticated session. Unauthenticated
/api/*calls fail closed. Production operator access is need-to-know. - Multi-factor authentication — TOTP (and SMS) available on all accounts. Required for internal admin accounts. Recommended if you upload labs.
- Audit logging — We log authentication events and selected health-data reads (labs, export, coach). Logs are designed not to include transcripts, lab values, or message bodies. They are an operational trail, not a tamper-proof archive.
- Account deletion — Deleting your account schedules permanent erasure within 30 days. Export first from Profile → Export.
Your data, our scores
Your raw health data remains yours. Kosei computes proprietary scores and indices for your account. Our scoring logic — including the Kosei Health Index, dimension weights, and organ-system models — is proprietary to Kosei.
Where scores incorporate documented public formulas (for example, PhenoAge-style biological age estimates), we document methodology in-app and cite primary literature. See our Terms of Service for the full split.
Subprocessors
These vendors process data so we can run the membership. They work under their own terms and data-processing addenda. They are not HIPAA business associates of Kosei, because Kosei is not a HIPAA covered entity or business associate on this product.
| Vendor | Purpose | Data handled |
|---|---|---|
| Fly.io | Application hosting and compute | Running app; application logs (health payloads excluded by policy) |
| Neon | Managed Postgres | Account and health data at rest |
| xAI / Grok | Coach K, transcription, lab extraction | Minimized health context after you consent; they can read what we send |
| Upstash Redis | Rate limits and short-lived session state | Ephemeral keys; not a system of record |
| Stripe | Payment processing | Billing identity and payment methods |
| Amazon S3 | Lab PDF objects when configured | Encrypted objects keyed to your account |
| Sentry | Error monitoring | Stack traces and sanitized request metadata (no bodies, cookies, or emails) |
| Resend | Transactional email | Email address and message content only |
Coach K and AI processing
Before your first Coach K conversation, we ask for consent to send health context to xAI (Grok). That context can include labs, wearable summaries, meals, training, and life notes — enough for the coach to be useful. xAI processes that text to return a reply. We do not claim they cannot read it.
You can review sources and privacy detail in our Privacy Policy. Calendar events marked private stay out of prompts.
Report a security issue
If you discover a vulnerability or have a security question, email longevitycorner@gmail.com with the subject line Security. We aim to acknowledge reports within 3 business days.
Please do not publicly disclose issues until we have had a chance to respond.