Skip to content
Vitana
Inside VitanaPrivacySecurityDownload
Get launch updates
Security overview

Local-first is the boundary, not the whole answer.

Vitana combines encrypted per-profile storage, OS-backed key protection, local-network pairing controls, and narrow data access to reduce where sensitive health data can travel.

Encrypted profile storage

Each desktop profile has a separate AES-256-GCM encrypted DuckDB database. The packaged desktop app generates a random data key, wraps it with the operating system's secure storage, and keeps only the wrapped form on disk.

The Android companion's Standalone mode uses a SQLCipher-encrypted SQLite database and protects its key with Android secure storage.

Paired local connections

The desktop API becomes available on the local network only for companion use. Production connections require HTTPS and pin the certificate public-key hash established during pairing.

Companion tokens are revocable and bound to the assigned profile and capability set. A paired phone does not receive general access to other profiles.

Backups and recovery

Portable backups use a versioned, password-protected AES-256-GCM format with bounded decompression and per-profile integrity digests. Restore stages each profile separately, checks parity, and promotes the replacement database only after hydration succeeds.

Keep backup passwords separate from backup files. Loss of the OS-protected desktop key can otherwise make local profile databases unreadable.

Optional AI boundaries

Cloud model access is off by default and requires explicit consent for each profile. When enabled, Vitana applies provider allowlisting, public-address checks, manual redirect handling, redaction, bounded query results, and SELECT-only query compilation.

Local analytics and locally configured Ollama processing do not require sending the prompt to a cloud provider.

Report a vulnerability

Do not file public GitHub issues for security vulnerabilities. Contact the maintainer privately using the details on the GitHub profile and include impact, reproduction steps, and the tested version or commit.

Reports are acknowledged within 72 hours. Vitana follows a 90-day coordinated disclosure window and will not take legal action against researchers acting in good faith.

Scope and limitations

Weaknesses in LAN transport, encrypted storage, pairing, authorization, input validation, backup and recovery, dependencies, and cloud-prompt minimization are in scope.

Vitana is a wellness application. It does not diagnose conditions, prescribe treatment, recommend medication changes, or handle urgent medical concerns.

Vitana

A private workspace for understanding your health data.

PrivacySecurityDownloadGitHub
© 2026 Vitana HealthWellness information, not medical advice.