Security

Security and data handling

Technical documentation contains design details, test results and supplier data. This page describes the controls MDRpilot actually has in place today, in plain language.

Company data isolation

Every product, document, evidence file and quality record belongs to one company workspace. Server-side checks scope each request to the signed-in user's company, so one company's records are not returned to another.

  • Evidence files are not served from a public folder. Downloads require a signed-in session in the owning company.
  • Internal template and storage paths are blocked from public access.

Access control

Workspace members have one of five roles: Owner, Quality manager, Regulatory affairs, Consultant or Viewer. Actions such as approving documents, changing settings or deleting data are limited by role.

Authentication

  • Passwords are stored as bcrypt hashes, never in plain text.
  • Optional two-factor authentication with time-based one-time passwords (TOTP). TOTP secrets are stored encrypted with AES-256-GCM.
  • Sessions use httpOnly cookies that page scripts cannot read.
  • Email verification and password reset flows are built in.

Transport and browser protections

  • HTTPS with HTTP Strict Transport Security (HSTS).
  • Content Security Policy, X-Frame-Options DENY, X-Content-Type-Options nosniff, a strict Referrer-Policy and a restrictive Permissions-Policy.

AI processing

  • AI drafting runs on the server; provider API keys never reach the browser.
  • When live AI is used, relevant excerpts are sent to configured AI providers (for example OpenAI or Anthropic) only to produce the requested output.
  • A company owner can turn off external AI processing for the whole workspace in Settings.
  • Without a live AI provider the platform runs on a deterministic built-in engine, so non-AI workflows keep working.
  • Controlled templates lock document headings; AI fills section bodies, and statements that cannot be confirmed from company data are marked [TO BE CONFIRMED] instead of being invented.

Traceability inside the workspace

An activity log records who changed, approved or generated what, so document history can be shown during an audit.

Deletion and retention

Users can delete their own account in Settings, and a company owner can request deletion of the company workspace. Retention, including backup cycles, is described in the Privacy Policy.

What we do not claim

This page does not claim third-party security certifications or attestations. If your procurement process needs a security questionnaire, a data processing agreement or a list of sub-processors, contact us and we will answer from facts.

Contact

Security questions and vulnerability reports: support@mdrpilot.com. Privacy and data protection requests: privacy@mdrpilot.com. See also the Privacy Policy.

See it with your own device

Create an account, add your company and one real device. The Suite demo runs for 3 days and the first procedure opens straight away, not an empty dashboard.