MedVault
Security
Last updated: July 15, 2026
This page describes the security controls that are currently enabled in MedVault. It is maintained by the MedVault team and is not an independent certification.
Authentication
- Email and password sign-in with securely hashed credentials handled by our managed authentication provider.
- Optional single sign-on with Google.
- Session tokens are short-lived and refreshed transparently.
Access control
- Every record, doctor, and profile row is protected by row-level access policies that scope reads and writes to the authenticated owner.
- Uploaded files live in a private storage bucket. They can only be accessed through short-lived signed URLs issued to the file's owner.
Encryption
- All traffic is served over HTTPS/TLS.
- Data is encrypted at rest by the underlying managed infrastructure.
Data handling
- MedVault does not sell your data and does not use your medical records to train machine-learning models.
- You can delete records, files, and your account at any time — see the Privacy Policy.
Reporting a vulnerability
If you believe you have found a security issue, please report it responsibly through our Contact page before public disclosure. We appreciate coordinated disclosure and will respond as quickly as we can.
Shared responsibility
Security is a shared responsibility. We operate the platform controls above; you are responsible for keeping your password safe, using a unique password, and signing out on shared devices.
This page is maintained by the MedVault team and describes the app's current practices. It is not a legal opinion or an independent certification. For questions, see Contact.