Current design: supported health records are stored in an encrypted local Health Vault. Sensitive AI request and response bodies are encrypted end to end between the browser and a verified Tinfoil enclave. Catina still operates account, authentication, routing, rate-limit, billing, and reliability systems.
Feature-by-feature data map
| Feature | Primary location | Data involved | Boundary |
|---|---|---|---|
| Account and plan | Catina service | Account identifier, plan status, authentication and abuse-prevention metadata | Needed to operate accounts, limits, and paid access |
| Health Vault | Your browser/device | Imported lab, genetics, lifestyle, and supported health records | Encrypted local storage; your Catina sign-in helps unlock the vault on your device |
| Extra Local Protection | Your browser/device | An additional encrypted vault layer | A separate passphrase gives you sole responsibility for access and recovery |
| Sensitive AI request body | Attested Tinfoil enclave | The content needed for the selected analysis | Encrypted in the browser with EHBP after verification; decrypted only inside the selected enclave |
| Relay metadata | Catina relay and network providers | Headers and operational signals such as authentication, route, limits, timing, and usage | Request and response bodies stay protected; operational metadata remains visible |
| Public site analytics | Catina analytics endpoint | Aggregate page and event data when configured | Configured to respect Do Not Track and exclude search terms |
Two ways to protect your Health Vault
Standard protection
Your health records are encrypted and stored in your browser. Signing in to Catina unlocks the vault automatically on your device. Catina's account service supports this convenient sign-in and recovery experience.
Extra Local Protection
For more control, you can add a separate passphrase that stays in your browser. Your browser uses it to apply another layer of encryption before opening the vault. Access and recovery depend on the passphrase you keep, so save it securely alongside your original files and an encrypted vault backup.
Sensitive AI request flow
- 1
Verification
The browser SDK checks that the encryption key belongs to an attested secure enclave running the expected measurement.
- 2
Secure session
After verification, the browser establishes the encrypted request path. A verified session may be cached and refreshed for up to 30 minutes, with attestation occurring when the secure session is established or refreshed.
- 3
Encrypted relay
The body is encrypted at the application layer. Catina's relay adds authentication and routes it while preserving EHBP headers.
- 4
Enclave inference
The selected enclave decrypts the protected body, runs the model path, and encrypts the response body back to the browser.
- 5
Fail closed
A verification or secure-setup failure stops the sensitive request before transmission.
Verification Center evidence
The in-app Verification Center displays the verification state for the current sensitive AI destination and links to implementation evidence. Remote attestation identifies the measured enclave that accepted the encrypted body. This evidence covers the enclave destination; device integrity, network metadata, medical answer quality, and non-E2EE product areas remain separate concerns.
Read Tinfoil's attestation architecture and encrypted proxy documentation.
Trust assumptions and limits
- Security depends on the integrity of your browser, operating system, device, and extensions.
- The browser must receive and execute the intended Catina and Tinfoil client code.
- Hardware vendors, attestation roots, enclave measurements, and the audited software supply chain remain part of the trust base.
- EHBP protects request and response bodies. Headers, timing, IP-derived network data, token counts, and account metadata remain visible to the services that operate the request.
- End-to-end encryption applies to supported sensitive AI request and response bodies. Catina's public site, authentication, payment, community, support, and other operational surfaces use their respective service protections.
Authoritative links
Privacy policy · AI information · Editorial methodology · Terms