Skip to content
Medovac
Trust center

Security is the foundation, not a feature

Medovac is built for regulated industries where a data breach is not an option. Security and privacy are designed into the platform from the data plane up, and validated by independent auditors.

SOC 2 Type II
Security, availability, and confidentiality
ISO/IEC 27001
Information security management
GDPR
EU data protection compliance
HIPAA
Protected health information ready
CCPA
California consumer privacy
ISO/IEC 27701
Privacy information management
How we protect data

Defense in depth

Encryption everywhere

Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Key material is managed through a dedicated key management service with regular rotation.

Least-privilege access

Role-based access control, SSO and SAML, and enforced multi-factor authentication govern every entry point. Production access is time-boxed and fully audited.

Isolated data planes

Enterprise customers can run in a dedicated VPC or fully on-premise, so regulated data never leaves an environment you control.

Continuous monitoring

Our own Sentinel engine watches infrastructure and application telemetry around the clock, with anomaly detection tuned to catch intrusions and misconfigurations early.

Auditable lineage

Column-level lineage and immutable audit logs mean every data access and model decision can be traced end to end for compliance and incident response.

Secure development

Mandatory code review, automated dependency and secret scanning, and regular third-party penetration testing are built into our engineering lifecycle.

Architecture

Built to keep data in your control

Medovac connects to your lakehouse through read-only, scoped credentials. Wherever possible, computation is pushed down to your own warehouse so that raw data stays in place. For customers with the strictest requirements, the entire data plane runs inside your cloud account or on-premise, with only metadata and orchestration signals crossing the boundary.

Every environment is logically isolated per tenant. Secrets are stored in a dedicated vault, never in code or configuration, and access to production requires just-in-time approval that expires automatically.

Responsible disclosure

We welcome reports from security researchers. If you believe you have found a vulnerability in a Medovac product or service, please email our security team with details and steps to reproduce. We commit to acknowledging your report within two business days and to keeping you updated as we investigate and remediate.

security@medovac.com

Please do not publicly disclose an issue until we have had a reasonable opportunity to address it. We do not pursue legal action against researchers who act in good faith.

Data handling

Your data, your terms

Data ownership

You own your data at all times. We process it solely to provide the service, never to train shared models across customers.

Data residency

Choose where your data plane runs. Regional deployments keep data within the jurisdictions you require.

Deletion on request

When a contract ends, we delete customer data within the contractually agreed window and provide written confirmation.

Looking for our subprocessor list, penetration test summary, or SOC 2 report? Reach out to security@medovac.com and we will share them under NDA.

See Medovac on your own data

Book a technical walkthrough with our field data science team. We will connect a sample of your data and show governed, production-grade intelligence in under an hour.