Data Security

Built secure for Indian families

This page is maintained by MyMi Health to describe security controls currently in place. It is not an independent certification.

๐Ÿ” TLS / HTTPS

Every request between your phone and our servers is encrypted in transit.

๐Ÿ“ฑ Firebase OTP 2FA

All accounts use phone OTP. No passwords to leak or reuse.

๐Ÿงฑ Row-level isolation

Postgres Row Level Security ensures each user only sees their own rows.

๐Ÿ‡ฎ๐Ÿ‡ณ India-hosted

Primary database in Supabase ap-south-1 (Mumbai). No cross-border data transfer.

๐Ÿ—„๏ธ Encryption at rest

Database and storage volumes are encrypted at rest by the cloud provider.

๐Ÿ›ก๏ธ Least privilege

Service accounts are scoped to the minimum operations they need.

Incident response

If we detect or are notified of a security incident affecting user data, we triage within 24 hours, contain and remediate immediately, and notify affected users and CERT-In within statutory timelines. Post-incident learnings are documented and shared in this page.

Responsible disclosure

Found a vulnerability? Please email support@mymihealth.com with details. We acknowledge within 3 working days and work with you on a fix before public disclosure.