Trust centre
Security at NutriHub
NutriHub uses layered account, application and database controls designed for practice and contact information.
Last updated: 26 August 2026
Access protection
- Separate professional and contact authentication journeys.
- Optional multi-factor authentication, with practice-level enforcement for staff.
- Custom roles and permissions, owner-protected controls and team-member approval.
- Recent multi-factor verification for sensitive administrative changes.
Data isolation and secure delivery
- Organisation-scoped database rules and automated isolation tests.
- Private document and image storage with short-lived access links where appropriate.
- Encrypted HTTPS connections and restrictive browser security headers.
- Signed webhooks and protected scheduled-delivery endpoints.
- Branded sending domains become active only after DNS verification.
Development and monitoring
- Automated application, database-security and public-journey checks on GitHub changes.
- Dependency vulnerability checks and locked dependency versions.
- Security and activity events for sensitive portal and practice operations.
- Read-only production availability checks with support references that exclude care data.
Your responsibilities
Security is shared. Practice owners must review team access, protect account factors, configure integrations carefully, remove former staff promptly and avoid sharing sensitive records through ordinary email or support messages.
Report a security concern
Send a concise report to support@nutrihub.health. Include the affected area and what you observed, but do not send passwords, MFA codes or complete contact records. Do not access, change or download information that is not yours.