Security Practices

Last Updated: January 11, 2026Version: 1.3

Our Commitment to Security

At myCARI, protecting your health information is our top priority. We employ industry-leading security measures to ensure your data remains private and secure. As a healthcare application handling Protected Health Information (PHI), we implement security controls that meet or exceed HIPAA requirements.

Compliance Framework

StandardStatusDescription
HIPAAImplementedSecurity controls aligned with HIPAA requirements; BAA signed with GCP
SOC 2 Type IIVia InfrastructureGCP infrastructure is SOC 2 certified
GDPRImplementedData protection practices aligned with GDPR
CCPAImplementedCalifornia Consumer Privacy Act requirements addressed

Technical Security Measures

Encryption

LayerTechnologyDetails
In TransitTLS 1.3All network communications use the latest TLS encryption
At RestAES-256All stored health data encrypted with industry-standard encryption
Key ManagementGoogle Cloud KMSAutomatic key rotation, hardware security modules
End-to-EndCurve25519 + AES-256-GCMCare team messages encrypted on-device before transmission

End-to-End Messaging Encryption

Care team messages are protected with true end-to-end encryption:

  • Messages are encrypted on your device before being sent
  • Only the sender and intended recipients can decrypt messages
  • The server only stores encrypted data - it cannot read your messages
  • Conversation previews show "Encrypted message" to protect content
  • Each recipient receives a uniquely encrypted copy using their public key

Authentication

FeatureImplementation
Biometric LoginFace ID and Touch ID support (recommended)
Social Sign-InApple Sign-In, Google Sign-In available
Session ManagementToken-based sessions with automatic expiration
Brute Force ProtectionRate limiting and account protection mechanisms

Infrastructure Security

ComponentDetails
Cloud ProviderGoogle Cloud Platform (HIPAA BAA signed)
Data CentersGCP SOC 2 certified data centers, US-based
Web Application FirewallCloud Armor with OWASP rule sets, DDoS protection
DatabaseCloud SQL with AES-256 encryption, private IP connectivity
Secrets ManagementGoogle Secret Manager for all credentials

Data Isolation and Multi-Tenancy

myCARI implements strict data isolation to ensure user data cannot be accessed by other users:

FeatureImplementation
Container IsolationEach user's health data stored in isolated containers
Database SeparationUser data partitioned with row-level security
Care Team AccessPermission-based access with full audit logging
Professional ModeProfessional caregivers have separate audit trails

Audit Logging

We maintain comprehensive audit logs of all security-relevant activities:

Event TypeDetails Logged
AuthenticationLogin attempts, logouts, password changes
Data AccessAll access to health information
Data ModificationsChanges to health records, medications, vitals
Care Team ActionsMember additions, removals, permission changes
API AccessAll API calls with timestamps and results

Retention: Audit logs are retained for 6 years per HIPAA requirements. Logs cannot be modified after creation.

Your Role in Security

To help keep your health data secure:

PracticeWhy It Matters
Use a strong passwordPrevents unauthorized account access
Enable Face ID/Touch IDAdds biometric layer of protection
Keep your iPhone updatedSecurity patches protect against vulnerabilities
Keep myCARI updatedApp updates include security improvements
Don't share your loginYour credentials are for your use only
Review care team accessPeriodically verify who has access to your data

Reporting Security Issues

If you discover a security vulnerability:

Email: security@mlpipes.ai

Guidelines:

  • Provide detailed information about the vulnerability
  • Do not publicly disclose until we've addressed it
  • We appreciate responsible disclosure

We do not pursue legal action against security researchers who act in good faith, avoid accessing others' data, and give us reasonable time to respond.

Questions?

Address:
MLPipes LLC
5725 S Valley View Blvd Ste 5 PMB 471045
Las Vegas, Nevada 89118-3122 US