Private origin
The initial FATChat services are designed to sit behind Cloudflare Tunnel rather than exposing NAS application ports directly to the public internet.
Security
FATChat is being designed around private-by-default records, explicit authorization, protected application identity and infrastructure that can scale without changing who owns the data.
The initial FATChat services are designed to sit behind Cloudflare Tunnel rather than exposing NAS application ports directly to the public internet.
The authenticated application uses Clerk for account identity. FATChat keeps its own internal user IDs so product data is not coupled directly to an authentication vendor.
Access decisions for personal health records and Family Circles belong on the server, not in hidden buttons or client-only checks.
The architecture calls for tested backups, an off-NAS copy and a documented restore path rather than treating the production NAS as the only copy.
The product architecture distinguishes reversible archive/soft-delete workflows from permanent purge operations so data lifecycle behavior can be explicit.
FATChat does not claim that any system is “100% secure,” and this page does not claim HIPAA compliance or certifications that have not been formally established.
Until a dedicated security mailbox is published, use the contact page and choose Security as the topic. Do not include sensitive medical details in a security report unless necessary.
Contact FATChat