Trust & Safety

Security

Last updated: June 24, 2026

Protecting sensitive mental health data is core to our mission. Here's how we keep Snuggli and Sentra secure by design.

Our Security Approach

Security is foundational to Snuggli Health. Because we handle sensitive mental health and care coordination data, we design our platforms with a security-first mindset and a human-led, AI-assisted governance model.

Our security program follows recognized frameworks and is built around the principles of least privilege, defense in depth, and continuous improvement. This page summarizes how we protect our systems and the data entrusted to us.

Data Encryption

We protect data throughout its lifecycle:

  • Encryption in transit: all network traffic is secured using TLS with strong, modern cipher suites.
  • Encryption at rest: stored data is encrypted using industry-standard algorithms.
  • Key management: cryptographic keys are managed through secure key management services with restricted access and regular rotation.
  • Secure backups: backups are encrypted and access-controlled to support recovery without exposing data.

Access Control

We restrict access to systems and data on a need-to-know basis:

  • Role-based access control aligned with each user's responsibilities.
  • Multi-factor authentication required for all administrative and internal access.
  • Principle of least privilege, with access reviewed and revoked as roles change.
  • Comprehensive audit logging of access to sensitive systems and data.

Infrastructure Security

Our infrastructure is hosted on reputable cloud providers and configured to follow security best practices. We isolate environments, apply network segmentation, and continuously monitor for threats.

We maintain secure software development practices, including code review, dependency scanning, and automated testing, to reduce vulnerabilities before deployment.

Vulnerability Management

We work to identify and address security weaknesses proactively:

  • Regular security assessments and penetration testing by qualified professionals.
  • Continuous monitoring and patching of infrastructure and dependencies.
  • Threat modeling for new features and significant changes.
  • A responsible disclosure program to receive and act on security reports from external researchers.

Incident Response

We maintain an incident response plan to detect, contain, and remediate security incidents quickly. Our team is trained to follow defined escalation and communication procedures.

In the event of a confirmed security incident affecting personal data, we will notify affected users and relevant authorities as required by applicable law, and we will work transparently to resolve the issue.

Compliance and Standards

Our security and privacy practices are aligned with leading standards, including:

  • Data protection regulations such as the GDPR and equivalent regional privacy laws.
  • Healthcare data protection requirements where Sentra is deployed in clinical settings.
  • Recognized security frameworks for cloud and application security.
  • Safeguards appropriate to the protection of children's and young people's data.

Data Privacy and Protection

Security and privacy are inseparable. We minimize the data we collect, use it only for its intended purpose, and apply strict controls over sharing and retention. Our Privacy Policy describes these commitments in detail.

We do not sell personal data, and we limit third-party data sharing to what is necessary to operate and secure our services.

Business Continuity

We maintain backup, disaster recovery, and business continuity plans to ensure our platforms remain available and recoverable. Critical systems are designed for resilience, with regular testing of recovery procedures.

Responsible Disclosure

We welcome and appreciate responsible disclosure of potential security vulnerabilities. If you believe you have identified a vulnerability, please report it to security@snugglihealth.com with sufficient detail to reproduce the issue.

We ask that you avoid accessing or modifying data you do not own, and that you give us reasonable time to investigate and remediate before any public disclosure.

Security Contact

For security questions, concerns, or vulnerability reports, contact our security team at security@snugglihealth.com. For privacy-related inquiries, write to privacy@snugglihealth.com.