Health data, a fast-moving team, and no map of the risks.
Wellness apps often handle information that health-data rules care about, and a fast-moving startup rarely has time to check every access rule, database policy, and vendor agreement against them.
The founders wanted a clear, honest picture of where they stood against HIPAA and SOC 2, and a practical plan to fix what wasn’t right.
An end-to-end review of the app, the data, and the process.
We reviewed the React Native mobile app, the Supabase back end, and supporting infrastructure against both frameworks at once, and delivered a single unified audit report.
- Authentication, authorization, and database access policies
- Encryption, storage, and how health-related data moves through the system
- Logging, monitoring, and audit trails
- Every finding ranked by severity, with a specific fix
From unknown risk to a closed-out plan.
The team received a prioritized remediation plan they could act on immediately, and the gaps were remediated. Instead of discovering problems during a customer security review, they could answer those questions with confidence.