Security Controls

Trust & Security Center

Physitrack Group prioritizes the security and privacy of your data, offering global healthcare and wellbeing solutions with strong data protection measures.

Keep your private information private

Discover the steps we take and features we offer to safeguard your data and keep your information protected.

Our security is built to the highest standards

Learn how our in-house security team approaches information security and fortifies our product.

Enterprise-grade attestations validate our security controls

See the attestations and certifications that ensure our users' data is safe and secure.

Two Leading Brands, One Trusted Platform

Digital physiotherapy and rehabilitation platform connecting patients with licensed practitioners. Provides exercise prescription, progress tracking, and telehealth solutions for musculoskeletal conditions.

* Physitrack is registered with the United Kingdom Information Commissioner's Office under number ZA396165.

Comprehensive workplace wellbeing platform supporting employee mental health, physical wellness, and occupational health services for organizations of all sizes.

* Champion Health is registered with the United Kingdom Information Commissioner's Office under number ZA525188.

Security Governance & Leadership

Our security team uses top industry frameworks and continuous monitoring to ensure exemplary security practices. Leadership's commitment to security excellence fosters a culture of protection and compliance. We provide regular security training and have clear roles for data access and protection.

Vulnerability Management
  • Secure Development Lifecycle (SDLC) practices.
  • Proactive detection, prioritisation (CVE, CVSS scoring), and remediation of vulnerabilities.
  • Regular third-party penetration tests, with audit summaries available upon request.

Infrastructure Security

Robust security architecture with threat detection, network segmentation, and ongoing vulnerability assessments.

Infrastructure Security (AWS)
  • Secure AWS hosting with ISO 27001 and SOC 2-certified data centres.
  • Decentralised architecture to enhance resilience and fault tolerance.
  • Daily encrypted backups stored securely across multiple geographic regions.
  • Real-time service health status available online.
  • Our infrastructure is hosted on AWS, which manages physical and environmental security controls.

Network Security

Our network security includes segmentation, firewalls, and threat detection. We use automated CSPM for cloud security and monitor for threats continuously.

Application Security

Our anti-tampering measures, like code obfuscation and integrity checks, prevent unauthorized access. Regular audits and penetration tests ensure compliance with OWASP and NIST standards.

Vulnerability Management

We maintain security through a Secure Development Lifecycle (SDLC), identifying and addressing vulnerabilities using CVE and CVSS scoring. Regular third-party penetration tests are conducted, with audit summaries available upon request.

Payments Security

Payments are processed securely through PCI-DSS compliant third-party services, with no internal storage of payment data.

Data Encryption

Data is encrypted during transmission using TLS 1.2+ and at rest with AES-256. We ensure end-to-end encryption between devices and the cloud.

Access Control & Authentication

We use role-based access control (RBAC) to limit user access to necessary information. Multi-factor authentication (MFA) adds an extra security layer.

Compliance & Certifications

Comprehensive compliance with international standards including GDPR, HIPAA, and ISO 27001 certifications. Regular third-party audits and assessments ensure continuous adherence to the highest security and privacy standards.

Physitrack Group has an ISMS in place, with roles of Information Security Manager and Data Protection Officer appointed. Our adherence to the ISO requirements has been confirmed by the independent audits and is supported with the ISO27001 (Information Security) and ISO27018 (Data Protection in Cloud) certificates.

Data Protection & Privacy

Advanced encryption, secure data processing, and comprehensive privacy controls protect sensitive information at every stage.Transparent privacy practices with user control over data usage and clear consent mechanisms for all processing activities.

Data Protection Overview

Physitrack Group is committed to transparency and strict adherence to global data protection regulations, ensuring user rights are respected across all platforms. We prioritize the protection of personal and health information as a fundamental responsibility, building trust with our users.

Data Storage & Security Measures

  • Data stored securely within AWS environments, encrypted (AES-256 encryption standard).
  • Geographically compliant storage ensuring regional data residency.
  • Secure backups regularly performed, encrypted, and stored in separate locations.

Data Processing & Categories of Data

Physitrack Group processes personal and special category health data strictly for the purpose of delivering secure, effective healthcare and wellbeing services. The types of data processed vary slightly between our two products, Physitrack and Champion Health.

For a complete breakdown of the categories of data processed, please refer to our detailed Data Processing Agreements (DPAs).

Note: We are incorporated under UK law and registered with the ICO (the Information Commissioner's Office). We have clients in more than 100 countries. For these reasons, our DPAs are available in English only.

Our DPAs are:

  • Fully aligned with GDPR, UK GDPR, and relevant international regulations.
  • Supported by rigorous subprocessor audits and compliance checks.
  • Designed to ensure full transparency and customer rights, including objection to subprocessor changes.

User Rights & Transparency

  • Full user rights management: access, correction, deletion.
  • Transparent policies and procedures detailed clearly in privacy notices and terms of service.

Data Retention & Deletion

  • Data retained only as necessary per detailed retention policies.
  • Automatic secure deletion post-retention periods, externally audited.

Security Controls

Privacy-first

We ask and store as little as possible and have designed our platform and operations in line with the EU's strict GDPR principles. Non-EU subprocessors have Standard Contractual Clauses in place.

Data encryption in transit and at rest

All data sent to and from our platform is encrypted in-transit and encrypted at rest. See our SSL Labs score. All media between the client and server use standard protocols (DTLS/SRTP) encrypted with 256 bit AES.TLS encryption is used for inbound and outbound email.

HIPAA compliant

On top of all the controls that protect the confidentiality, integrity and availability of PHI, we have BAAs in place with third parties and subcontractors who have access to PHI.

Confidentiality & our team

Access to patient data is severely restricted, and any person or party that (potentially) has access to patient data is bound by confidentiality agreements.

Local storage in countries/regions

Physitrack runs physically isolated platforms in different data centers around the world to avoid leaking data outside jurisdictions as much as reasonably possible.

Security audits
  • Every year, we hire an accredited third party to perform grey box penetration tests on our platform. This includes testing for vulnerabilities against OWASP-threats
  • Every week, an independent third party scans our platform for known vulnerabilities.
    Any uncovered vulnerability is prioritised, resolved and deployed as soon as possible following discovery.
Network security
  • Our network security architecture consists of multiple security zones. We monitor and protect our network, to make sure no unauthorised access is performed using:

    - a virtual private cloud (VPC);
    - a bastion host or VPN with network access control lists (ACL’s) and no public IP addresses;
    - a firewall that monitors and controls incoming and outgoing network traffic;
    - IP address filtering.
Physical security

Our infrastructure is hosted inside AWS. Physical and environmental security related controls for our servers, which includes buildings, locks or keys used on doors, are managed by AWS:“Physical access is strictly controlled both at the perimeter and at building ingress points by professional security staff. Authorised staff must pass two-factor authentication a minimum of two times to access data center floors."

No payment information stored

Your privacy is of utmost importance to us. As part of our commitment to safeguarding your data, we do not store any bank or credit card information on our servers. Instead, we rely on PCI-DSS-certified third-party payment services to handle all transactions. They are industry leaders in payment security and compliance, ensuring that your payment information is processed securely and efficiently.
For payment processing, we utilise the following trusted services:

  • Adyen is a leading payment service known for its advanced technology and compliance with PCI-DSS standards. You can review their privacy practices on their privacy policy page.
  • Stripe is a globally recognised payment platform known for its robust security measures and compliance with PCI-DSS standards. You can learn more about their privacy practices by visiting their privacy policy page.
  • GoCardless specialises in direct debit payments and adheres to the highest security standards. Detailed information about their data protection and privacy policies can be found on their privacy policy page.
  • Chargebee offers a comprehensive subscription billing platform with robust security protocols. Please refer to their privacy policy for more details on how Chargebee handles your data.

Our commitment to your data security is further strengthened by our partnerships with these reputable trusted services. Together, we implement a comprehensive array of security measures, ensuring that your financial information is managed with the utmost care and security.

Secure Development Lifecycle

We use industry-best practice development processes both for our applications and our infrastructure.Code is under version control (Git), and features/fixes are developed in separate branches.Before being reviewed by a peer, code has to pass thousands of automated tests and is scanned for known security issues. The fix/feature is then manually tested (QA) and merged to the master code branch.We have separate testing, staging and production environments.

Is there any free courses?

Lorem ipsum dolor sit amet consectetur adipiscing elit Ut et massa mi. Aliquam in hendrerit urna.

Do I get certificates?

Lorem ipsum dolor sit amet consectetur adipiscing elit Ut et massa mi. Aliquam in hendrerit urna.

How to apply as Instructor?

Lorem ipsum dolor sit amet consectetur adipiscing elit Ut et massa mi. Aliquam in hendrerit urna.

Is this an interactive lessons?

Lorem ipsum dolor sit amet consectetur adipiscing elit Ut et massa mi. Aliquam in hendrerit urna.

Is there any free courses?

Lorem ipsum dolor sit amet consectetur adipiscing elit Ut et massa mi. Aliquam in hendrerit urna.

Do I get certificates?

Lorem ipsum dolor sit amet consectetur adipiscing elit Ut et massa mi. Aliquam in hendrerit urna.

How to apply as Instructor?

Lorem ipsum dolor sit amet consectetur adipiscing elit Ut et massa mi. Aliquam in hendrerit urna.

Is this an interactive lessons?

Lorem ipsum dolor sit amet consectetur adipiscing elit Ut et massa mi. Aliquam in hendrerit urna.

Responsible disclosure

Physitrack Group is committed to maintaining the highest standards of security and privacy for our users. We appreciate the support of the security community in responsibly identifying potential vulnerabilities in our platform.

Reporting a Vulnerability

If you believe you have discovered a security vulnerability in our systems, we encourage you to report it to us at security@physitrack.com. Please include as much detail as possible to help us investigate and resolve the issue efficiently.

Security issues: 24 hours | Privacy requests: 72 hours

For General Inquires

Our Commitment

  • We will acknowledge your report promptly and keep you informed throughout the remediation process.
  • We will treat your report confidentially and will not disclose your identity without consent.
  • We will not pursue legal action against you if you act in good faith and follow the principles of responsible disclosure.

Scope

This policy applies to vulnerabilities in services hosted under the Physitrack and Champion Health domains. Vulnerabilities in third-party services should be reported directly to those providers.

Out of Scope

  • Social engineering of Physitrack employees or contractors
    Physical attacks or attempts at physical intrusion
  • Denial of service (DoS) attacks or brute force testing