Last updated: July 28, 2026
Security at DoseForge starts with a simple principle: the safest data is the data we never hold. Your health records live on your device, we don’t run user accounts, and the few optional cloud features are engineered to see as little as possible. This page describes how we protect what does flow through our systems, and the certified infrastructure we rely on.
DoseForge has no usernames, passwords, or profiles. A device is identified only by a random, app-generated identifier. We can’t lose what we don’t collect — there’s no central database of who you are.
When you share inventory with a household, the data is end-to-end encrypted. Each household has a content key that never leaves members’ devices; our relay stores only ciphertext and members’ public keys, and authorizes each write by digital signature. The server literally cannot read the contents — it can’t even tell a vial from a draw. Keys are exchanged directly between members, device-to-device.
Card payments are processed entirely by Square. DoseForge never receives, processes, or stores your card number. Card data is handled within Square’s PCI-DSS Level 1 certified environment.
Image and document scanning runs on your device; only the resulting text is sent for analysis, and only the specific, de-identified text an analysis needs — never your name, identifiers, or photos. Requests are sent over TLS and processed solely to generate your result.
DoseForge’s cloud runs on Amazon Web Services using managed, scale-to-zero services (API Gateway, Lambda, DynamoDB, CloudFront, S3, KMS/Parameter Store). We rely on the security programs and independent certifications of our infrastructure providers:
These certifications are held by the respective providers for the infrastructure we use. DoseForge itself is a small, data-minimizing application and does not claim to independently hold these certifications; we describe them for transparency about the foundations our service is built on.
If you believe you’ve found a security vulnerability, please tell us before disclosing it publicly. Email hello@doseforge.app with the subject line “Security” and steps to reproduce. We appreciate good-faith reports and will work with you to resolve issues promptly.
Related: Privacy Policy · Record Retention Policy · Notice of Privacy Practices