Security Policy
How Medalock protects the information you share with it, and the practices behind the product.
Placeholder — pending legal review
This page sets out the structure and intent of the final document. It is not yet a binding legal text. Replace the sections below with counsel-approved wording before launch.
What we will publish here
This page will describe our security programme once each item is genuinely in place. We will not list a control before it is operational, and we will not name a certification before it is awarded.
- Encryption in transit and at rest, with the specifics
- Access control, least privilege and internal review
- Secure development practices and dependency management
- Logging, monitoring and incident response
- Business continuity and backup handling
- Vendor security review
- Independent assessments and certifications, once obtained
Practices already in force
- This website collects no account credentials. There is no password field anywhere on it.
- The security self-check is computed in the browser. Answers are never transmitted or stored.
- Analytics and advertising tags remain dormant until a visitor accepts the matching consent category.
- The site is served over HTTPS with HSTS, and sends conservative security headers including a strict referrer policy and a restrictive permissions policy.
Reporting a security issue
Email security@medalock.app. See our Responsible Disclosure page for what to include and what to expect.
