Company
Security practices
What ZHCLOUD LLC actually does to protect your account, stated without inflation. We are a small company and we are not going to claim a certification we do not hold.
Data protection in transit and at rest
- All traffic is served over TLS. Plain HTTP requests are redirected, and we send HTTP Strict Transport Security so browsers refuse to downgrade.
- Passwords are stored only as salted one-way hashes. We cannot read your password and we will never ask you for it.
- Database volumes and backups are encrypted at rest by our hosting provider.
- Backups are taken on a rolling schedule and restores are tested, because an untested backup is a guess.
Keeping sensitive records separate
Journal entries, symptom notes and birth time inputs get stricter handling than ordinary account data:
- They are logically isolated from marketing and analytics identifiers, so a usage event can never carry a wellness field.
- They never appear in URLs, application logs, crash reports or support ticket subject lines.
- They are excluded from third-party analytics entirely, and we verify that by inspecting outbound requests at field level before a release rather than trusting the configuration.
- They are deleted when you withdraw consent, not merely flagged as withdrawn.
Access control
- Production access is limited to the smallest number of people who need it, currently the founder.
- Administrative accounts require multi-factor authentication.
- Access is reviewed quarterly, and removed the same day a contractor's engagement ends.
- Administrative actions on user accounts are logged.
Payments
Card details are entered directly into our payment provider's hosted form and never reach our servers. ZHCLOUD LLC stores only a payment token, the card brand, the last four digits and the transaction outcome. Entitlements are granted only after a signed, verified confirmation from the provider, so a forged callback cannot unlock a paid plan. See the billing terms.
Application hardening
- Rate limiting on authentication and on expensive endpoints.
- Cross-site request forgery protection on state-changing requests.
- Session cookies marked
HttpOnly,SecureandSameSite. - Security response headers including a frame policy, a referrer policy and content-type sniffing protection.
- Dependencies monitored for known vulnerabilities and patched on a regular cycle.
- An automated test suite that gates releases, including checks that our compliance and disclaimer requirements are still satisfied.
What we do not claim
We hold no SOC 2, ISO 27001 or HIPAA attestation, and we are not a HIPAA covered entity or business associate. We do not operate a 24-hour security operations centre. We are a small company with a deliberately small attack surface, and we would rather tell you that plainly than imply an assurance we cannot evidence. No system is perfectly secure.
Reporting a vulnerability
Email security@e5elements.com with enough detail to reproduce the issue. Our commitments to you:
- We acknowledge within 1 business day.
- We give you an assessment and a remediation plan within 5 business days.
- We will credit you when we publish a fix, if you want us to.
- We will not pursue legal action against good-faith research that stays within the boundaries below.
Please, while testing:
- Use only your own account and your own data.
- Do not run denial-of-service tests, spam, or social engineering against our staff or users.
- Do not access, modify or retain another person's data; if you encounter it accidentally, stop and tell us.
- Give us reasonable time to fix an issue before disclosing it publicly.
We do not currently run a paid bug bounty. We will say so honestly rather than imply a reward that does not exist.
If something goes wrong
If personal data is exposed in a way that creates a risk to you, we notify affected users and the
relevant authorities within the deadlines that apply to us. We treat an unauthorised disclosure of
wellness information to any third-party tool as a reportable incident rather than an ordinary bug.
Our machine-readable contact details are published at
/.well-known/security.txt.
Related
Privacy policy · Access, export and deletion · Acceptable use policy