< Defibrio Manual

Appendix E: Security

Defibrio employs multiple techniques to protect your data and keep the AED, the app, and your phone safe.

Access to user data requires login
You need to create a username and password to register your device, order new pads, or access your contact info. The Defibrio collects EKG signals during emergency events, and that data is anonymous and only stored to be directly shared with medical professionals.

Secure communications and storage
The Defibrio app and the Defibrio AED module communicate via an encrypted and authenticated communication channel. The Defibrio AED has no connectivity of its own: it communicates only through a connected phone, and all communication between the Defibrio App and backend servers requires authentication. The Defibrio App encrypts all data stored on the smartphone.

Security logging
The Defibrio system logs attempted security breaches. If a security breach is attempted, you will be notified via your Defibrio account. Security log files are stored securely and accessible only through authenticated Defibrio communication channels: they are not intended to be used or accessed by the consumer.

End of device life support and decommissioning
No sensitive, confidential, or proprietary data is stored on the AED module. Before discarding your smartphone, follow the smartphone manufacturer’s procedure for removing apps and remove the Defibrio app. This will remove all your data associated with the Defibrio App. To remove your data from Defibrio’s servers, or for end of device life and support information, please contact Defibrio at info@defibrio.com.

Software Bill of Materials (SBOM)
To receive a machine-readable Software Bill of Materials (SBOM) for the Defibrio Personal AED, please contact Defibrio at info@defibrio.com.

Defibrio User’s Guide version 4.0, for model # 00860010539903