Current measures
- Business login is handled via federated OAuth/OpenID Connect.
- API keys for appointment delivery belong to a single environment and are stored only as a hash.
- Integration tokens are stored on the server side and encrypted before being permanently retained.
- Browser clients do not receive provider secrets or Firebase service credentials.
- Business actions are designed for audit logging at the platform holder level.
Planned controls
- Formal mapping to ISO/IEC 27001 controls.
- NEN 7510 assessment for healthcare implementations.
- Advanced webhook signature validation and key rotation management.
- Retention and deletion automation per environment and data category.
Additional encryption — planned
Encryption of personal data and copies in appointment and delivery records, with separate key management, is planned. This does not guarantee protection against every data breach.
Encryption and app distribution
Before the first app release, we will assess the encryption and, where required, French declarations and Apple export documentation. An Apple approval code is not an encryption key or a security certification. No approval has yet been confirmed.
Dont4get does not claim any ISO, NEN, or SOC certification on this page as long as such certification has not been formally achieved.