Skip to main content
Medfolio
Security

How Medfolio protects your data.

Encryption, authentication, and access controls — explained plainly. Built for medical records, not as an afterthought.

Encrypted in transit & at restDPDP-alignedHosted in Mumbai
01 · Encryption

Encrypted everywhere.

Medical records move through Medfolio with the same kind of cryptography that banks and tax authorities use for their most sensitive data.

TLS 1.3 in transit
Every request between your phone and our servers — every upload, every share-link click, every API call — flows over TLS 1.3. Older protocols are refused.
AES-256 for files at rest
PDFs, photos, and scans are stored in object storage (AWS S3) with server-side AES-256 encryption. Encryption keys are managed by AWS KMS with rotation policies.
pgcrypto for PII
Personally-identifying database columns — phone numbers, names, dates of birth — are encrypted at the column level using PostgreSQL pgcrypto with per-tenant keys.
Hosted in India
All data lives in AWS Mumbai (ap-south-1). No cross-border transfer for regular operations.
02 · Authentication

Only you, only your devices.

Sign-in is built on short-lived tokens with strict rotation. Sensitive actions ask for a fresh verification, even on a trusted device.

OTP-only sign-in
No passwords to leak. Sign in with a phone number and an SMS code. The OTP is single-use and short-lived; failed attempts trigger lockout.
JWT with short expiry + refresh rotation
Access tokens expire in minutes. Refresh tokens rotate on every use — a stolen refresh token is invalidated as soon as the legitimate device refreshes.
Device tracking
Every active session shows up in your Settings. Revoke a device in one tap; that token is invalidated server-side immediately.
Re-verification for sensitive actions
Deleting reports, deleting your account, or sharing whole-profile data triggers a fresh OTP, even on a logged-in device.
03 · Access controls

Sharing without surrender.

Every share link Medfolio generates is scoped, time-limited, OTP-verified, and audited. You stay in control after you press send.

Per-recipient share tokens
Each share generates its own token — bound to the recipient, the scope, and the expiry. No two shares are interchangeable.
Scope-limited
Share a single report, a test panel across visits, or a whole profile — but only what you select. The recipient sees nothing else.
Expiry on every link
24 hours, 7 days, 30 days, or a custom date. After expiry the OTP refuses to work and the share moves to your archived list.
Revoke any time
One tap revokes the link. Active recipients are signed out immediately; new viewers can't open the link at all.
Full audit log
See every open, every device, every download. Downloaded PDFs are watermarked with the recipient name and access timestamp on every page.
04 · What we don't do

The promises that aren't in the small print.

We don't sell data

Your reports, your timeline, your trends — none of it is for sale, in aggregate or otherwise. Our revenue comes from optional paid features, not from your data.

We don't train AI on your records

Your uploads are processed for your account only. The extraction model is trained on synthetic and consented public datasets, never on user records.

We don't share with insurers or labs

No backchannel partnerships. Insurers, labs, and pharmacies see what you choose to share with them through a Medfolio share link — and nothing else.

05 · Incidents

If something goes wrong.

No system is 100% impenetrable, and we won't pretend otherwise. If a breach occurs that affects user data, our policy is to notify affected users per the requirements of India's Digital Personal Data Protection (DPDP) Act, 2023 — including by direct in-app notification, email where on file, and disclosure to the Data Protection Board where required.

We publish a summary of any material security incident on this page within 72 hours of confirmation, including: what was affected, what data was exposed, what we've done, and what (if anything) you need to do.

Reporting a vulnerability: if you believe you've found a security issue, email security@medfolio.co.in. We acknowledge within 48 hours and don't pursue legal action against good-faith researchers who follow responsible-disclosure practice.

Private by design. Yours by default.

Keep your family's reports in a place built to protect them.

Coming soon to Google Play. Coming soon on the App Store.