Security First Architecture

Your health data is yours.
We just protect it.

We believe privacy shouldn't require a law degree to understand. We use banking-grade encryption and security-first engineering to keep your family's data safe.

A+
SSL Labs Rating

Top-tier transport security

A+
Mozilla Observatory

Web security best practices

100%
Encrypted

In-transit and At-rest

How we secure your data

Encryption Everywhere

We utilize AES-256 encryption for data at rest (when it's stored in our database) and TLS 1.3 for data in transit (when it moves between your phone and our servers). This is the same standard used by modern banking apps.

Privacy-First Business Model

We are not in the business of selling data. Unlike free apps that mine your health history for advertisers, MedsAi is a subscription service. You are the customer, not the product.

Minimal Data Retention

When we sync to your calendar, we push updates using a secure "One-Way" feed. We do not read the other contents of your calendar, and we only retain the medication logs necessary to provide you with your history.

Regulatory Note

While MedsAi utilizes Security Infrastructure (provided by Amazon Web Services and Google Cloud) and adheres to industry-standard security practices, MedsAi is a direct-to-consumer health tool and is not currently classified as a "Covered Entity" under HIPAA.

We maintain these high standards voluntarily because we believe your data deserves the highest level of protection, regardless of regulatory requirements.