Trust & transparency

Your health, well protected

Sahha handles sensitive health data. Here is, honestly, what is actually in place today — and what is still being built.

Our security approach

🔑

Authentication and sessions

  • Passwords hashed with PBKDF2-SHA256, 210,000 iterations (OWASP recommendation)
  • Signed-token sessions, httpOnly and secure cookie
  • Automatic account lockout after repeated failed logins
  • Field-level encryption for sensitive medical data: being rolled out
🇪🇺

Hosting

  • Hetzner servers, Helsinki and Falkenstein data centers (European Union)
  • TLS-encrypted traffic
  • Cloudflare CDN for static content only
  • No transfer outside the EU without a legal basis
📋

Legal compliance

  • Processing compliant with Moroccan law 09-08 (data protection), under CNDP oversight
  • CNDP declaration in progress
  • Privacy policy and legal notices published and up to date
  • Right of access, rectification and deletion on request
🛡️

Access controls

  • Audit log on access to sensitive data
  • Rate limiting on authentication routes and forms
  • Strict role separation (patient, physician, administrator)
  • Time-limited sessions with renewal
🧪

Ongoing security

  • Code review on changes touching authentication and sensitive data
  • Open responsible disclosure channel (see below)
  • External audit program being structured
  • Priority fixes for any reported vulnerability
👥

Patient privacy

  • No resale of personal data to third parties
  • No advertising profiling based on medical data
  • Export your data on request
  • Account deletion available on request
🐛

Found a vulnerability?

We appreciate security researchers. If you find a flaw, please report it via [email protected].

⏱️ Response within 48h

Acknowledgement on business days

🔍 Reviewed seriously

Every report is reviewed and fixed as a priority

📅 90-day disclosure

We ask for 90 days before any public disclosure

/.well-known/security.txt (RFC 9116)

Policies & legal documents