Skip to content

Security

Your data security is our first priority. This page sets out how we protect your information, where it is stored, and who can reach it.

Data encryption

All data transmitted between your device and our servers is encrypted using TLS 1.3. Your data at rest is encrypted using AES-256, the same standard used by financial institutions and government agencies.

EU data residency

Your data is stored exclusively on servers located in the European Union (Ireland). This supports GDPR compliance and gives you the strongest data protection standards available.

  • All databases hosted in EU data centres
  • No data transfers outside the EU
  • Regular third-party security audits
  • SOC 2 Type II compliant infrastructure

Authentication security

Vestibola uses email and password sign-in only. There is no third-party social login, so no external provider sits between you and your account.

  • Passwords hashed with bcrypt and never stored in readable form
  • Mandatory email verification before an account can be used
  • Sessions held in session storage and cleared on sign-out
  • Automatic timeout after a period of inactivity
  • Rate limiting and protection against brute-force attempts

Row-level security

We implement row-level security policies on all database tables. Users can only reach their own records, which is an additional layer of protection beyond application-level access controls.

Privacy by design

Vestibola is built with privacy at its core. We follow the principle of data minimisation, collecting only the information necessary to provide the service. Your client data remains under your control at all times.

  • No tracking of your clients' personal information
  • Anonymisation tools built into the clinical notes editor
  • Complete data export available at any time
  • Right to erasure honoured on request

GDPR compliance

As a platform designed for mental health professionals handling special category health data, we treat data protection as a product feature rather than a policy document. A Data Processing Agreement is presented and recorded before you reach the account area, and explicit consent is taken for health data processing.

Incident response

In the unlikely event of a security incident, we have an incident response plan in place. We will notify affected users within 72 hours as required by GDPR and take immediate steps to mitigate any potential harm.

Security questions?

If you have questions about our security practices, or would like to report a vulnerability, write to security@vestibola.com and we will respond promptly.