Security Transparency

Security at MediWing

MediWing is built and operated by MediMindLab, Inc. We design for defense-in-depth and apply security controls aligned with recognized healthcare-security practices. This page summarizes our current controls and transparency commitments. For our full data-handling practices, see our Privacy Policy.

Encryption & Storage

Data Protection

  • Encryption in transit: all traffic protected with HTTPS/TLS.
  • Encryption at rest: sensitive health information — extracted document text, analysis results, conversation history, and health-timeline data — encrypted at rest using AES-256-GCM.
  • Password protection: passwords hashed with bcrypt; never stored in plain text.
  • Data isolation: database row-level security enforces complete separation between users; no cross-user data access is possible.
Access & Accountability

Access & Audit Controls

  • Authenticated access: all data APIs require authentication, and you can access only your own records.
  • Audit logging: access to protected health information is recorded in an append-only audit log, consistent with the HIPAA Security Rule audit-controls standard (45 CFR § 164.312(b)).
  • Session protection: account lockout after repeated failed logins, and automatic idle-session timeout.
  • Signed document access: private documents are served through expiring, signed access links.
  • Rate limiting: applied to authentication, upload, and analysis endpoints.
  • Payment integrity: payment webhook events are signature-verified.
Operations

Operational Safeguards

  • Secret management: credentials are stored in server-side configuration and are never exposed to the browser.
  • Restricted internals: debug and administrative endpoints are restricted and disabled in production.
  • Reduced data capture: error reporting is configured to minimize capture of sensitive data.
  • Continuous remediation: security issues are reviewed and remediated on an ongoing basis.
AI Privacy

AI Data Handling

  • Document text is sent to our AI provider (Anthropic) only to generate your analysis, on a transient basis.
  • Your name, email, and account identity are never sent to the AI provider.
  • Your documents and health information are not used to train AI models — ours or the provider's.
Third-Party Assurance

Audited Infrastructure

  • Database: Supabase, which maintains SOC 2 Type II.
  • Payments: Stripe, which maintains PCI DSS Level 1.
Commitment

Compliance Posture & Transparency

MediWing applies HIPAA-aligned security safeguards. For individual consumers, MediWing is an educational tool and is not a HIPAA “covered entity.” For healthcare organizations, MediMindLab, Inc. is prepared to act as a Business Associate and to execute a Business Associate Agreement (BAA) governing protected health information.

There is no government-issued “HIPAA certification” for software; we demonstrate our posture through implemented controls, documentation, and agreements. Institutional partners may request our security documentation and BAA at security@medimindlab.com.

For security or privacy requests, contact security@medimindlab.com or privacy@medimindlab.com.

Not a medical provider. MediWing provides educational health-document analysis and is not a substitute for professional medical advice, diagnosis, or treatment.