Last updated June 14, 2026
Security is the product. This page summarizes how Medusyx protects your data and how to report a vulnerability.
Every customer is strictly isolated — your data is segregated so that one customer can never see another's, and your most sensitive material is protected so that only you can unlock it.
Your data is encrypted in transit and at rest.
Sign-in supports single sign-on (Google, Microsoft, Apple, GitHub) and password login, with multi-factor authentication available. Passwords are always hashed, sessions are short-lived, and internal access follows least-privilege principles.
Privileged and security-relevant actions are recorded in an append-only audit log, giving you and us an accountable record of what happened and when.
The Service runs on hardened, reputable cloud infrastructure, with sensitive components isolated from the rest of the platform.
We build secure-by-default: least privilege, dependency hygiene, secret scanning before release, and review of any change that touches authentication, isolation or data handling.
We welcome reports from security researchers. Email [email protected] with details and steps to reproduce. Please act in good faith, only test against your own tenant, avoid privacy violations and service disruption, and give us reasonable time to remediate. We will not pursue legal action against good-faith research that follows these guidelines.
Our controls are designed to align with recognized frameworks such as SOC 2 and ISO/IEC 27001. Where formal attestations are in progress, we'll share status with customers under NDA.
We maintain an incident-response process and will notify affected customers of confirmed security incidents that materially affect their data, consistent with our obligations and applicable law.
Questions? [email protected] · [email protected] · [email protected]