Security approach

Authority, isolation and recovery are product requirements.

GFD is designed so operational convenience does not become coaching or data authority. This page describes principles, not a guarantee or a disclosure of attack-sensitive configuration.

Exact-athlete isolation

Application and database access are scoped to an exact tenant, user and athlete. Private objects and asynchronous work retain that scope.

Bounded authority

Health/restriction authority, PlanAuthority, consent and explicit proposal approval remain separate controls. Background delivery and retries do not become mutation authority.

Recovery and lifecycle

Database restoration, private-object recovery, export, revocation and deletion are exercised independently. A backup is not treated as healthy until restoration and isolation are verified.

Current limitations

The product remains in private development. Professional privacy/legal/clinical review and physical-device accessibility acceptance remain gates before Athlete #1.