Security

Last updated 4 August 2026

Less stored, less at risk

The strongest security control here is architectural: there is no account database, no report library and no long-term storage of health information. A breach cannot expose a history that does not exist.

Handling uploads

  • Files are identified by their actual contents, not their extension.
  • Uploads are screened before any parser reads them.
  • Password-protected PDFs are rejected rather than opened.
  • Document metadata is stripped before processing.
  • Files are capped at 20 MB and 30 pages.

In transit and at rest

Everything runs over TLS. Temporary storage is encrypted, reachable only through short-lived signed links, and carries an expiry rule independent of the application.

Logging

Report contents, values, marker names and filenames never enter our logs. Error reporting does not capture request bodies from the analysis pages.

Reporting a vulnerability

Use the contact form and choose Security report. Please do not include any laboratory data in your report to us.

Security · LabTestsResults.com