Skip to content
Medalock
Back to Medalock
Legal

Security Policy

How Medalock protects the information you share with it, and the practices behind the product.

Placeholder — pending legal review

This page sets out the structure and intent of the final document. It is not yet a binding legal text. Replace the sections below with counsel-approved wording before launch.

What we will publish here

This page will describe our security programme once each item is genuinely in place. We will not list a control before it is operational, and we will not name a certification before it is awarded.

  • Encryption in transit and at rest, with the specifics
  • Access control, least privilege and internal review
  • Secure development practices and dependency management
  • Logging, monitoring and incident response
  • Business continuity and backup handling
  • Vendor security review
  • Independent assessments and certifications, once obtained

Practices already in force

  • This website collects no account credentials. There is no password field anywhere on it.
  • The security self-check is computed in the browser. Answers are never transmitted or stored.
  • Analytics and advertising tags remain dormant until a visitor accepts the matching consent category.
  • The site is served over HTTPS with HSTS, and sends conservative security headers including a strict referrer policy and a restrictive permissions policy.

Reporting a security issue

Email security@medalock.app. See our Responsible Disclosure page for what to include and what to expect.

$9/mo per protected platform