Security
The security of your health data is our responsibility and yours. This page shows what we do, what you can do and how to reach us.
O que fazemos
- Connection protected by HTTPS on every access.
- Sign-in with a one-time code, with no password to remember or to be stolen.
- Profile-based access: each person sees only what they need, and each institution has its data kept separate.
- Video consultation with image and audio encrypted in transit and no recording.
- Technical team access limited to what is needed to keep the service running, and logged.
- Fixing flaws and updating the system as routine.
We use recognized information security best practices as a reference, such as ISO/IEC 27001 and 27701 and the ANPD security guide. This does not mean we are certified to those standards.
What we ask you to do
- Check the address: it should start with https:// and show the padlock in the browser.
- Do not share the access code with anyone, not even someone who says they are from our team.
- Use a trusted device and network. Avoid public Wi-Fi for consultations.
- On shared devices, sign out when you finish.
- Keep your browser and device system up to date.
- Take the consultation in a private place.
We never ask for your password or payment outside the site
VYKA never asks for your password, access code or payment by phone, e-mail or WhatsApp. The access code is entered only on the sign-in page of our site.
Be wary of urgency
Messages that demand immediate action, promise prizes, ask for data or contain strange links may be scams. If in doubt, do not click and contact our support through an official channel.
If you fall for a scam
- Change the password of your e-mail and of the accounts linked to it.
- Let us know at [email protected], with the subject “Security alert”.
- File a police report. Electronic fraud is a crime (Penal Code, art. 171, para. 2-A, added by Law No. 14,155/2021).
Found a flaw?
If you find a security flaw, let us know at [email protected], with the subject “Security alert”. Please do not access other people's data, do not run tests that affect the service and give us a reasonable time to fix it before disclosing. We appreciate the care.
If there is an incident
If a security incident occurs that may cause relevant risk or harm, we notify the ANPD and the people affected, as required by art. 48 of the LGPD and CD/ANPD Resolution No. 15/2024.
Reference standards
- LGPD (Law No. 13,709/2018), arts. 46 to 49: security, confidentiality and good practices.
- Brazilian Internet Civil Framework (Law No. 12,965/2014), art. 10, and Decree No. 8,771/2016, art. 13: retention and protection of data and communications.
- Law No. 12,737/2012: hacking of a computer device as a crime (Penal Code, art. 154-A).
- Law No. 14,155/2021: electronic fraud.
- CD/ANPD Resolution No. 15/2024: reporting of security incidents.