Security

How LongevAI protects the information entrusted to us. Last updated: August 2026

Our commitment

LongevAI protects the confidentiality, integrity and availability of the information entrusted to us. Our controls are proportionate to risk and to the sensitivity of the data, with priority given to the health data processed through LongevOS. Our top management has established an Information Security Policy that binds every person working for LongevAI, and reviews it at least annually.

Certification status

We are working towards ISO/IEC 27001:2022 certification. Our Stage 1 audit was completed in July 2026 with no non-conformities raised. Stage 2 follows. We are not yet certified and do not claim to be. We comply with the GDPR and the Dutch UAVG today, independently of that process.

AI and your patients' data

Google Cloud (Vertex AI, Gemini) is our sole AI sub-processor for patient health data. That processing runs under a data processing agreement with EU data residency, and your data is never used to train models. We also use other AI providers for internal tooling; those providers never receive patient or health data.

Access and encryption

Access follows the principle of least privilege, and we apply the following as standard:

  • Multi-factor authentication is mandatory for production systems, cloud infrastructure and source code
  • Access rights are reviewed at least every six months, and revoked no later than the last working day on termination or role change
  • Shared accounts are prohibited on production systems
  • Data in transit is protected with TLS 1.2 or higher; data at rest with AES-256 or equivalent
  • Encryption keys are held with restricted access and rotated on the schedule set out in our cryptography policy

Secure development

Security is built into our development process from design onward. Every change to LongevOS is peer reviewed before it reaches production. Our pipelines scan dependencies for known vulnerabilities on every relevant change, and our source code is analysed by scheduled automated static security analysis. Secrets are never committed to repositories; they are held in managed secret stores and rotated on a defined schedule. Production is separated from development and staging, and production data is not used for testing without authorisation and masking.

Incidents and breach notification

Suspected incidents are reported immediately to our Information Security Manager and triaged within one hour of detection, including an assessment against the GDPR 72-hour notification duty where personal data is involved. Where Article 33 requires it, we notify the Autoriteit Persoonsgegevens within 72 hours, and affected individuals under Article 34. All incidents are recorded and investigated, and significant incidents receive a root cause analysis.

Continuity, backup and suppliers

We maintain documented business continuity and disaster recovery plans with defined recovery time and recovery point objectives for critical systems. Backups run on a defined schedule, are stored securely, and are tested for recoverability at least annually. Vendors that process our information are assessed for security before engagement and annually thereafter, and carry contractual security and incident-notification obligations. A data processing agreement is in place before any third party processes personal data on our behalf.

Our people

Everyone completes security awareness training before receiving system access and annually thereafter, with completion recorded. Signing our Acceptable Use Policy and a confidentiality agreement is a condition of engagement. Personnel with access to health data are screened to the extent permitted by law.

Requesting our Information Security Policy

This page summarises our Information Security Policy. The full policy is classified for internal use, because it names individual responsibilities and the internal structure of our management system. We make it available to clients, prospective clients, auditors and other interested parties on request, under a confidentiality agreement where appropriate. Write to info@longevai.nl.

Reporting a vulnerability

If you believe you have found a security vulnerability in any LongevAI service, write to info@longevai.nl with enough detail to reproduce it. We will confirm receipt and keep you informed while we investigate. Please give us a reasonable period to resolve the issue before disclosing it publicly.