Log in

Security

How we protect your health data.

Effective August 18, 2026 v3.0 — consumer wellness, current product

The short version

01

What Kosei is (and is not)

Kosei is a paid precision-health membership operated from New Jersey. You buy Kosei for yourself. We are not a healthcare provider, not a health plan, and not a HIPAA covered entity. We do not process health data on behalf of a clinic, employer, or insurer.

HIPAA business associate agreements (BAAs) do not apply to this product. A BAA is a HIPAA contract used when a vendor handles protected health information for a covered entity. That is not our model. If we ever offered Kosei to a clinic, employer, or health plan, that would be a separate program with different contracts. We refuse those deals until that program exists.

Kosei is not HIPAA-compliant and does not claim covered-entity or business-associate status. The controls below are what we actually run. We do not market a HIPAA certification we do not have.

02

Technical controls

  • Encryption in transit — TLS 1.2+ on every connection. HSTS in production.
  • Encryption at rest (application) — AES-256-GCM for OAuth tokens, Coach K messages, voice transcripts, lab names and values, lab PDF objects, and Coach K cache payloads. Production refuses to store those fields if the encryption key is missing.
  • Encryption at rest (infrastructure) — Neon and Fly encrypt volumes. Wearable metrics, meals, workouts, and scores are protected by access control and vendor disk encryption, not a second application-layer cipher.
  • Access — Health APIs require an authenticated session. Unauthenticated /api/* calls fail closed. Production operator access is need-to-know.
  • Multi-factor authentication — TOTP (and SMS) available on all accounts. Required for internal admin accounts. Recommended if you upload labs.
  • Audit logging — We log authentication events and selected health-data reads (labs, export, coach). Logs are designed not to include transcripts, lab values, or message bodies. They are an operational trail, not a tamper-proof archive.
  • Account deletion — Deleting your account schedules permanent erasure within 30 days. Export first from Profile → Export.
03

Your data, our scores

Your raw health data remains yours. Kosei computes proprietary scores and indices for your account. Our scoring logic — including the Kosei Health Index, dimension weights, and organ-system models — is proprietary to Kosei.

Where scores incorporate documented public formulas (for example, PhenoAge-style biological age estimates), we document methodology in-app and cite primary literature. See our Terms of Service for the full split.

04

Subprocessors

These vendors process data so we can run the membership. They work under their own terms and data-processing addenda. They are not HIPAA business associates of Kosei, because Kosei is not a HIPAA covered entity or business associate on this product.

VendorPurposeData handled
Fly.ioApplication hosting and computeRunning app; application logs (health payloads excluded by policy)
NeonManaged PostgresAccount and health data at rest
xAI / GrokCoach K, transcription, lab extractionMinimized health context after you consent; they can read what we send
Upstash RedisRate limits and short-lived session stateEphemeral keys; not a system of record
StripePayment processingBilling identity and payment methods
Amazon S3Lab PDF objects when configuredEncrypted objects keyed to your account
SentryError monitoringStack traces and sanitized request metadata (no bodies, cookies, or emails)
ResendTransactional emailEmail address and message content only
05

Coach K and AI processing

Before your first Coach K conversation, we ask for consent to send health context to xAI (Grok). That context can include labs, wearable summaries, meals, training, and life notes — enough for the coach to be useful. xAI processes that text to return a reply. We do not claim they cannot read it.

You can review sources and privacy detail in our Privacy Policy. Calendar events marked private stay out of prompts.

06

Report a security issue

If you discover a vulnerability or have a security question, email longevitycorner@gmail.com with the subject line Security. We aim to acknowledge reports within 3 business days.

Please do not publicly disclose issues until we have had a chance to respond.