Security

Questions about this page? Write to mednais@samplify.org.

This page says what MedNAIS™ does and what it does not claim. It is not a certification statement, and the section at the bottom is the honest part of it.

How one organisation is kept apart from another

Tenancy is enforced in the database itself, by row-level security policies, rather than by the application remembering to filter. A query that forgets which organisation it is asking about is refused by the database rather than quietly answered. Every policy reads the signed-in identity directly, so a mistake in application code cannot widen what a person may write.

Who may do what

Three roles — owner, administrator, member — and the authority between them is enforced by the database too, not only by hiding buttons. An administrator can invite and remove members but cannot make another administrator; an organisation is never left without an owner. Invitation links carry an expiry, a limit on how many times they can be used, and optionally a restriction to one e-mail domain.

Sign-in

Google, Apple, a one-time code sent to a work e-mail address, or a password you set yourself — held in the customary irreversible form, never in plain text. If you set no password we hold none for you. All of them reach the same account when the address is the same.

In transit and at rest

  • HTTPS only. The mobile clients refuse a server address that does not match the one they were built for.
  • Customer data at rest is in managed PostgreSQL in the European Union (Stockholm). Who else receives what, and where they are, is listed in the privacy policy.
  • No advertising network, no attribution SDK and no crash reporter is shipped in the mobile apps.

Reporting a problem

Write to mednais@samplify.org before telling anyone else. We will not pursue anyone who reports a vulnerability in good faith and gives us a reasonable chance to fix it.

What we do not hold, and do not claim

  • No security certification or attestation. No SOC 2, no ISO/IEC 27001, no independent audit report. If a questionnaire asks for one, the answer is that we do not have it.
  • No HIPAA claim and no Business Associate Agreement. MedNAIS is not designed to hold protected health information and should not be used to hold it.
  • No single sign-on with a corporate identity provider — no SAML, no SCIM provisioning. The sign-in options are the four listed above.
  • No published penetration test report and no bug bounty programme.
  • No uptime commitment. We have not agreed a service level unless a separate written agreement with your organisation says so.

A data processing agreement we can do, and a security questionnaire we will answer as accurately as this page. Ask us.