Security is the foundation, not a feature
Medovac is built for regulated industries where a data breach is not an option. Security and privacy are designed into the platform from the data plane up, and validated by independent auditors.
Defense in depth
Encryption everywhere
Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Key material is managed through a dedicated key management service with regular rotation.
Least-privilege access
Role-based access control, SSO and SAML, and enforced multi-factor authentication govern every entry point. Production access is time-boxed and fully audited.
Isolated data planes
Enterprise customers can run in a dedicated VPC or fully on-premise, so regulated data never leaves an environment you control.
Continuous monitoring
Our own Sentinel engine watches infrastructure and application telemetry around the clock, with anomaly detection tuned to catch intrusions and misconfigurations early.
Auditable lineage
Column-level lineage and immutable audit logs mean every data access and model decision can be traced end to end for compliance and incident response.
Secure development
Mandatory code review, automated dependency and secret scanning, and regular third-party penetration testing are built into our engineering lifecycle.
Built to keep data in your control
Medovac connects to your lakehouse through read-only, scoped credentials. Wherever possible, computation is pushed down to your own warehouse so that raw data stays in place. For customers with the strictest requirements, the entire data plane runs inside your cloud account or on-premise, with only metadata and orchestration signals crossing the boundary.
Every environment is logically isolated per tenant. Secrets are stored in a dedicated vault, never in code or configuration, and access to production requires just-in-time approval that expires automatically.
Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability in a Medovac product or service, please email our security team with details and steps to reproduce. We commit to acknowledging your report within two business days and to keeping you updated as we investigate and remediate.
security@medovac.comPlease do not publicly disclose an issue until we have had a reasonable opportunity to address it. We do not pursue legal action against researchers who act in good faith.
Your data, your terms
Data ownership
You own your data at all times. We process it solely to provide the service, never to train shared models across customers.
Data residency
Choose where your data plane runs. Regional deployments keep data within the jurisdictions you require.
Deletion on request
When a contract ends, we delete customer data within the contractually agreed window and provide written confirmation.
Looking for our subprocessor list, penetration test summary, or SOC 2 report? Reach out to security@medovac.com and we will share them under NDA.
See Medovac on your own data
Book a technical walkthrough with our field data science team. We will connect a sample of your data and show governed, production-grade intelligence in under an hour.