Data Security
Built secure for Indian families
This page is maintained by MyMi Health to describe security controls currently in place. It is not an independent certification.
๐ TLS / HTTPS
Every request between your phone and our servers is encrypted in transit.
๐ฑ Firebase OTP 2FA
All accounts use phone OTP. No passwords to leak or reuse.
๐งฑ Row-level isolation
Postgres Row Level Security ensures each user only sees their own rows.
๐ฎ๐ณ India-hosted
Primary database in Supabase ap-south-1 (Mumbai). No cross-border data transfer.
๐๏ธ Encryption at rest
Database and storage volumes are encrypted at rest by the cloud provider.
๐ก๏ธ Least privilege
Service accounts are scoped to the minimum operations they need.
Incident response
If we detect or are notified of a security incident affecting user data, we triage within 24 hours, contain and remediate immediately, and notify affected users and CERT-In within statutory timelines. Post-incident learnings are documented and shared in this page.
Responsible disclosure
Found a vulnerability? Please email support@mymihealth.com with details. We acknowledge within 3 working days and work with you on a fix before public disclosure.
