Security
Security and data handling
Technical documentation contains design details, test results and supplier data. This page describes the controls MDRpilot actually has in place today, in plain language.
Company data isolation
Every product, document, evidence file and quality record belongs to one company workspace. Server-side checks scope each request to the signed-in user's company, so one company's records are not returned to another.
- Evidence files are not served from a public folder. Downloads require a signed-in session in the owning company.
- Internal template and storage paths are blocked from public access.
Access control
Workspace members have one of five roles: Owner, Quality manager, Regulatory affairs, Consultant or Viewer. Actions such as approving documents, changing settings or deleting data are limited by role.
Authentication
- Passwords are stored as bcrypt hashes, never in plain text.
- Optional two-factor authentication with time-based one-time passwords (TOTP). TOTP secrets are stored encrypted with AES-256-GCM.
- Sessions use httpOnly cookies that page scripts cannot read.
- Email verification and password reset flows are built in.
Transport and browser protections
- HTTPS with HTTP Strict Transport Security (HSTS).
- Content Security Policy, X-Frame-Options DENY, X-Content-Type-Options nosniff, a strict Referrer-Policy and a restrictive Permissions-Policy.
AI processing
- AI drafting runs on the server; provider API keys never reach the browser.
- When live AI is used, relevant excerpts are sent to configured AI providers (for example OpenAI or Anthropic) only to produce the requested output.
- A company owner can turn off external AI processing for the whole workspace in Settings.
- Without a live AI provider the platform runs on a deterministic built-in engine, so non-AI workflows keep working.
- Controlled templates lock document headings; AI fills section bodies, and statements that cannot be confirmed from company data are marked [TO BE CONFIRMED] instead of being invented.
Traceability inside the workspace
An activity log records who changed, approved or generated what, so document history can be shown during an audit.
Deletion and retention
Users can delete their own account in Settings, and a company owner can request deletion of the company workspace. Retention, including backup cycles, is described in the Privacy Policy.
What we do not claim
This page does not claim third-party security certifications or attestations. If your procurement process needs a security questionnaire, a data processing agreement or a list of sub-processors, contact us and we will answer from facts.
Contact
Security questions and vulnerability reports: support@mdrpilot.com. Privacy and data protection requests: privacy@mdrpilot.com. See also the Privacy Policy.
Related
- MDRpilot product profileCompany, category, modules, supported regulations, languages, pricing and contacts in one place.Read more
- AI for medical device regulatory work, with guardrailsHow AI can support medical device regulatory affairs without inventing facts: controlled templates, confirmed company facts, human approval and a workspace-level opt-out.Read more
- Privacy PolicyPrivacy Policy.Read more
- Terms of ServiceTerms of Service.Read more
See it with your own device
Create an account, add your company and one real device. The Suite demo runs for 3 days and the first procedure opens straight away, not an empty dashboard.
