Skip to main contentSkip to main content
Skip to content

SECURITY & TRUST

Your Data, Protected

Security is not an afterthought at ENLIVEN AI. As an EU-based company, we build privacy and data protection into every layer of our platform from day one.

GDPR-Native Architecture

Compliant

SIA Enliven is incorporated in Latvia, EU. GDPR compliance is built into every layer of our platform — from data collection consent flows to automated data subject request handling and right-to-erasure support.

Encryption at Rest & In Transit

AES-256

All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Authentication tokens are managed through AWS Cognito with KMS-backed encryption for sensitive operations like email verification codes.

AWS Cloud Infrastructure

AWS

Our entire platform runs on Amazon Web Services (us-east-1) with multi-AZ redundancy. We leverage API Gateway, Lambda, DynamoDB, S3, and CloudFront — all SOC 2 Type II certified services.

Authentication & Access Control

Cognito

User authentication is handled by AWS Cognito with MFA support. API endpoints are protected by Cognito authorizers with JWT validation. Role-based access control separates user, admin, and organization permissions.

Data Minimization

Privacy

We collect only what is needed to deliver personalized wellness recommendations. Health data is processed on-device where possible (ML Vision runs locally via MediaPipe). We never sell user data to third parties.

Secure API Design

5 APIs

All 5 API Gateways enforce rate limiting, CORS restrictions, and request validation. Webhook endpoints use signature verification. Admin APIs are isolated on separate gateways with independent authorizers.

Data Practices

Transparency First

What We Collect

  • Account information (name, email)
  • Workout logs and exercise history
  • Body metrics (optional — weight, height, body fat)
  • Biometric data from wearables (optional — heart rate, sleep)
  • EATS readiness inputs (subjective ratings)
  • ML Vision pose data (processed on-device, not stored)

What We Never Do

  • Sell your personal data to third parties
  • Share health data with advertisers
  • Store raw camera footage from ML Vision
  • Track you across other websites
  • Retain data after account deletion beyond legal requirements
  • Use your data to train models without explicit consent

Compliance

Compliance Roadmap

Our current certifications and planned compliance milestones.

GDPR (EU General Data Protection Regulation)Compliant
DKIM + DMARC Email AuthenticationActive
HTTPS Everywhere (TLS 1.3)Active
SOC 2 Type II (AWS Infrastructure)AWS Certified
SOC 2 Type II (ENLIVEN Application)Planned 2027
HIPAA CompliancePlanned 2027
ISO 27001 CertificationPlanned 2027
Penetration Testing (Third-Party)Planned Q3 2026

Have Security Questions?

We are happy to discuss our security practices in detail. Contact our team for security documentation, DPA requests, or compliance inquiries.