Public proof

How Catina protects your health data

See how local vault storage, browser encryption, enclave inference, and service metadata work across Catina.

Architecture verified August 20, 2026

Current design: supported health records are stored in an encrypted local Health Vault. Sensitive AI request and response bodies are encrypted end to end between the browser and a verified Tinfoil enclave. Catina still operates account, authentication, routing, rate-limit, billing, and reliability systems.

Feature-by-feature data map

FeaturePrimary locationData involvedBoundary
Account and planCatina serviceAccount identifier, plan status, authentication and abuse-prevention metadataNeeded to operate accounts, limits, and paid access
Health VaultYour browser/deviceImported lab, genetics, lifestyle, and supported health recordsEncrypted local storage; your Catina sign-in helps unlock the vault on your device
Extra Local ProtectionYour browser/deviceAn additional encrypted vault layerA separate passphrase gives you sole responsibility for access and recovery
Sensitive AI request bodyAttested Tinfoil enclaveThe content needed for the selected analysisEncrypted in the browser with EHBP after verification; decrypted only inside the selected enclave
Relay metadataCatina relay and network providersHeaders and operational signals such as authentication, route, limits, timing, and usageRequest and response bodies stay protected; operational metadata remains visible
Public site analyticsCatina analytics endpointAggregate page and event data when configuredConfigured to respect Do Not Track and exclude search terms

Two ways to protect your Health Vault

Standard protection

Your health records are encrypted and stored in your browser. Signing in to Catina unlocks the vault automatically on your device. Catina's account service supports this convenient sign-in and recovery experience.

Extra Local Protection

For more control, you can add a separate passphrase that stays in your browser. Your browser uses it to apply another layer of encryption before opening the vault. Access and recovery depend on the passphrase you keep, so save it securely alongside your original files and an encrypted vault backup.

Sensitive AI request flow

  1. 1

    Verification

    The browser SDK checks that the encryption key belongs to an attested secure enclave running the expected measurement.

  2. 2

    Secure session

    After verification, the browser establishes the encrypted request path. A verified session may be cached and refreshed for up to 30 minutes, with attestation occurring when the secure session is established or refreshed.

  3. 3

    Encrypted relay

    The body is encrypted at the application layer. Catina's relay adds authentication and routes it while preserving EHBP headers.

  4. 4

    Enclave inference

    The selected enclave decrypts the protected body, runs the model path, and encrypts the response body back to the browser.

  5. 5

    Fail closed

    A verification or secure-setup failure stops the sensitive request before transmission.

Verification Center evidence

The in-app Verification Center displays the verification state for the current sensitive AI destination and links to implementation evidence. Remote attestation identifies the measured enclave that accepted the encrypted body. This evidence covers the enclave destination; device integrity, network metadata, medical answer quality, and non-E2EE product areas remain separate concerns.

Read Tinfoil's attestation architecture and encrypted proxy documentation.

Trust assumptions and limits

  • Security depends on the integrity of your browser, operating system, device, and extensions.
  • The browser must receive and execute the intended Catina and Tinfoil client code.
  • Hardware vendors, attestation roots, enclave measurements, and the audited software supply chain remain part of the trust base.
  • EHBP protects request and response bodies. Headers, timing, IP-derived network data, token counts, and account metadata remain visible to the services that operate the request.
  • End-to-end encryption applies to supported sensitive AI request and response bodies. Catina's public site, authentication, payment, community, support, and other operational surfaces use their respective service protections.

Authoritative links

Privacy policy · AI information · Editorial methodology · Terms