Skip to main content

    Security at ViscaCare

    Last updated: 27 August 2026

    This page is the single source of truth for how we protect what you store with us. We describe only what we actually do — if a claim isn't on this page, we don't make it.

    Encryption at rest

    Documents and extracted health details in your vault are encrypted with AES-256-GCM before they are written to storage. Each member vault has its own data key, and that key is itself encrypted (“wrapped”) with a separate master key held only in our server environment and never stored in the database alongside your data. Traffic between your device and our servers is encrypted in transit with TLS.

    Unlocking your vault

    Reading vault content requires a step-up check: we text a one-time code to your verified mobile number, and the unlock lasts a short session (10 minutes) before it expires. You can add documents and organise folders without unlocking; reading the contents always requires the step-up.

    Who can decrypt your records

    • You, after a one-time-code unlock on your own account.
    • People you explicitly share with — a family member, carer or a doctor — for the folders and time window you choose. Shares can be revoked at any time and expire on their own.
    • Ask Mia, only when you ask it something that needs a record. Mia is given short, pseudonymised excerpts tied to a token rather than your identity, not whole documents.

    ViscaCare staff have no in-product route to decrypt and read your vault contents, and every access event is written to an access log you can view yourself. We are being deliberate with words here: this is strong isolation with logged access, and we do not describe it as “zero-knowledge” encryption, because our servers do hold the keys needed to serve your documents back to you.

    Deletion

    Deleting your vault destroys its encryption key, which makes the remaining ciphertext permanently unrecoverable (“crypto-shredding”), and the stored objects are then removed. You can delete your Ask Mia chat data separately at any time from Privacy & consent, and you can delete your whole account in-app.

    Where data lives, and access control

    Member data is held in EU-region infrastructure. Every table carries row-level security so a member can only ever reach their own rows, and those policies are re-audited automatically each night. Administrative accounts require a second factor by text message, and administrative actions are written to an immutable audit log.

    Reporting something

    If you believe you've found a security problem, email security@gewardz.com. We'll acknowledge within one working day. Please don't test against other members' accounts. For how we use data more broadly, see our Privacy Policy.