← Back to MicHelper
Business-Grade Security

Your Data, Protected

MicHelper is built with security and privacy at its core. We implement industry-standard practices to ensure your sales data remains confidential and protected.

🔐

Encryption in Transit

All connections to MicHelper use HTTPS with TLS 1.2 or higher. Data transmitted between your browser and our servers is always encrypted.

🔒

Encrypted Data at Rest

Sensitive data including transcripts and personal information is encrypted at rest using AES-256-GCM field-level encryption.

👥

Role-Based Access Control

Granular RBAC ensures users only see data relevant to their role. Sellers see their own data, managers see their teams, admins manage the network.

📋

Audit Logging

Actions are logged with timestamps, user IDs, and IP addresses. Full audit trail for compliance and security investigations.

⏱️

Rate Limiting

Global, per-user, and per-endpoint rate limiting protects against brute-force attacks and abuse. Suspicious activity is detected and blocked.

CSRF Protection

All state-changing API endpoints are protected with CSRF tokens, preventing cross-site request forgery attacks.

Technical Security Measures

We implement multiple layers of protection to safeguard your data.

Session Security

Secure session management with automatic timeouts, IP-based session validation, and brute-force protection with account lockout after failed login attempts.

HTTPS/TLS Encryption

HTTPS-only connections with HSTS enforcement. Security headers configured via Helmet.js (CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy).

Infrastructure

Hosted on SOC 2 certified infrastructure (Render). MicHelper inherits infrastructure-level security controls from the hosting provider. Data processed in United States. EU data center planned Summer 2026.

Input Validation & Injection Prevention

Parameterized SQL queries prevent injection attacks. XSS pattern detection on input. File upload validation with type and size limits.

Data Isolation

Each customer network is logically isolated. Cross-tenant access is architecturally prevented.

Authentication & Access Control

Data Protection

Infrastructure Security

Audit & Monitoring

Data Lifecycle

Data TypeRetentionEncryption
Raw audioDeleted immediately after transcriptionTLS in transit (transient processing)
TranscriptsPersist during subscriptionAES-256-GCM field-level
Analytics & scoresPersist during subscription + 30 daysDatabase-level
Account dataSubscription + 30 daysAES-256-GCM for sensitive fields
Audit logs90 daysDatabase-level

Privacy & Compliance

Designed with GDPR principles in mind. MicHelper helps you meet regulatory requirements while gaining valuable sales insights.

Designed with GDPR Principles in Mind

Built following GDPR principles: data minimization, purpose limitation, right to erasure, and data portability.

Data Processing Agreement

Standard DPA available for all customers. We act as a processor on your behalf.

Privacy Requests

In-app tools for data export and deletion requests. Respond to data subject requests efficiently.

Breach Notification

Documented incident response procedures. Notification within 72 hours as required by applicable law.

Data Lifecycle & Retention

Audio Recordings

Raw audio recordings are processed transiently. Audio is uploaded to our servers solely for the purpose of transcription. Once transcription is complete, the original audio file is permanently deleted immediately. Audio is never stored long-term on our servers.

Transcripts

Text transcripts generated from audio recordings persist during your subscription. Transcripts are a core service feature used for analytics, coaching, and reporting. Transcripts are encrypted at rest using AES-256-GCM field-level encryption.

Analytics, Scores & Performance Data

QA scores, coaching notes, event timelines, and metadata persist during your subscription plus 30 days after termination, to allow for data export. This data represents computed metrics and does not contain raw audio. Customers may request deletion through the account deletion process.

Account & Configuration Data

User accounts, network configurations, scripts, and system settings are retained for the duration of the active subscription and for 30 days following account termination to allow for data export.

Summary

Data Type Retention Encryption
Raw audio recordingsDeleted immediately after transcriptionAES-256-GCM (during processing)
TranscriptsPersist during subscriptionAES-256-GCM field-level
Analytics & scoresPersist during subscription + 30 daysDatabase-level encryption
Account dataDuration of subscription + 30 daysAES-256-GCM for sensitive fields
Audit logs90 daysDatabase-level encryption
🔒
TLS 1.2+ Transport Security
🗄️
AES-256 At-Rest Encryption
📊
SOC 2 Cloud Infrastructure (Render)
🛡️
GDPR Principles Privacy by Design

Security Commitment & Limitations

MicHelper implements industry-standard security measures to protect your data, including but not limited to:

No Absolute Guarantee. While we employ robust, multi-layered security controls and follow industry best practices, no system connected to the internet can guarantee 100% security. We commit to:

If you discover a potential security vulnerability, please report it responsibly to michelperhelp@gmail.com. We appreciate the security research community and will acknowledge valid reports.

Vulnerability Disclosure

We value the security research community and welcome responsible disclosure of security vulnerabilities.

Please do not access or modify other users' data, disrupt services, or publicly disclose vulnerabilities before we have had a reasonable opportunity to address them.

Questions About Security?

Our team is happy to discuss your specific security and compliance requirements.