MedVault

Security

Last updated: July 15, 2026

This page describes the security controls that are currently enabled in MedVault. It is maintained by the MedVault team and is not an independent certification.

Authentication

  • Email and password sign-in with securely hashed credentials handled by our managed authentication provider.
  • Optional single sign-on with Google.
  • Session tokens are short-lived and refreshed transparently.

Access control

  • Every record, doctor, and profile row is protected by row-level access policies that scope reads and writes to the authenticated owner.
  • Uploaded files live in a private storage bucket. They can only be accessed through short-lived signed URLs issued to the file's owner.

Encryption

  • All traffic is served over HTTPS/TLS.
  • Data is encrypted at rest by the underlying managed infrastructure.

Data handling

  • MedVault does not sell your data and does not use your medical records to train machine-learning models.
  • You can delete records, files, and your account at any time — see the Privacy Policy.

Reporting a vulnerability

If you believe you have found a security issue, please report it responsibly through our Contact page before public disclosure. We appreciate coordinated disclosure and will respond as quickly as we can.

Shared responsibility

Security is a shared responsibility. We operate the platform controls above; you are responsible for keeping your password safe, using a unique password, and signing out on shared devices.

This page is maintained by the MedVault team and describes the app's current practices. It is not a legal opinion or an independent certification. For questions, see Contact.