Security

How we protect your data · Last updated: 2026-05-09

1. The short version

WizeLife handles sensitive data — financial, medical, tax. We follow modern defense-in-depth practices: encrypted transport, encrypted storage, isolated user permissions, audited cloud providers, and a documented incident-response plan. We are a small team — we do not claim enterprise-grade certifications yet, but we apply the same engineering principles.

2. Encryption

3. Authentication & access control

4. Network & perimeter

5. Data minimization

We collect only what's required for each tool to work. We never collect:

Health data and high-sensitivity financial data are stored in browser localStorage by default and only synced to Firestore if you explicitly opt in.

6. AI processing

When you query our AI:

Full architecture: ARCHITECTURE.md (public).

7. Continuous monitoring

8. Incident response

If a data breach occurs:

  1. Affected users are notified via email within 72 hours (per Israeli Privacy Law and GDPR Article 33).
  2. The Israeli Privacy Protection Authority is notified, if required by the breach severity.
  3. A post-mortem is published on this page.
  4. Compromised credentials are forcibly rotated.

9. Vendor due diligence

Critical vendors and their compliance posture:

VendorRoleStandards
Google Firebase / CloudAuth + database + AISOC 1/2/3, ISO 27001/17/18, HIPAA-eligible
VercelFrontend hostingSOC 2 Type 2
Google Cloud RunBackend hostingSOC 2, ISO 27001
CloudflareDNS / WAF / DDoSSOC 2, ISO 27001
TavilyWeb search for AI groundingSOC 2 in progress
Cloudflare Web AnalyticsPrivacy-first analytics (no cookies)SOC 2, ISO 27001

10. Reporting a vulnerability

If you discovered a security issue, please email [email protected] with details and steps to reproduce. We respond within 48 hours.

Please:

We currently don't run a paid bug-bounty program, but we will publicly thank responsible reporters in this section.

11. Limitations & honest caveats

Things we don't have yet — and you should know:

12. Contact

Security questions or concerns: [email protected]
General: [email protected]