Facial data deserves serious handling.
This page is maintained by AiSkin to answer common security and privacy questions about the platform. It describes practices and enabled controls — it is not an independent certification.
All traffic is served over TLS 1.2+. Internal service calls are encrypted.
Stored images and assessments are encrypted at rest by the hosting platform.
Explicit, revocable consent is captured before any image is processed or retained.
Consumer scans are processed in memory and are not retained by default.
Any stored image or assessment can be deleted on request, with deletion propagated to backups on their rotation cycle.
Clinic and enterprise accounts scope data access by role — clinician, staff, admin.
Access to patient records and exports is logged with actor, action and timestamp.
Service credentials are scoped per environment and rotated without downtime.
Clinic admins can review what is stored, who accessed it, and export or purge it.
- GDPR. Facial imagery is treated as sensitive personal data. We support access, export and erasure requests, and process only on a documented lawful basis with explicit consent.
- HIPAA-ready architecture. Clinic deployments are built with the access controls, audit logging and encryption expected of a covered workflow. AiSkin is not itself a certified covered entity; a BAA is discussed during clinic onboarding.
- Not a medical device. AiSkin outputs are AI-generated skin assessments for educational and skincare-guidance purposes. They are not diagnostic and are not regulatory-cleared.
If you believe you have found a security issue, email security@aiskin.tech with reproduction steps. We acknowledge reports within two business days and will keep you updated through remediation. Please do not test against other people's data.