All MicHelper legal documents
Security

Your Data, Protected

MicHelper is built with security and privacy at its core. We implement industry-standard practices to ensure your sales data remains confidential and protected.

🔐

Encryption in Transit

All connections to MicHelper use HTTPS with TLS 1.2 or higher. Data transmitted between your browser and our servers is always encrypted.

🔒

Encrypted Data at Rest

Sensitive data including transcripts and personal information is encrypted at rest using AES-256-GCM field-level encryption.

👥

Role-Based Access Control

Granular RBAC ensures users only see data relevant to their role. Sellers see their own data, managers see their teams, admins manage the network.

📋

Audit Logging

Actions are logged with timestamps, user IDs, and IP addresses. Full audit trail for compliance and security investigations.

⏱️

Rate Limiting

Global, per-user, and per-endpoint rate limiting protects against brute-force attacks and abuse. Suspicious activity is detected and blocked.

CSRF Protection

All state-changing API endpoints are protected with CSRF tokens, preventing cross-site request forgery attacks.

Technical Security Measures

We implement multiple layers of protection to safeguard your data.

Session Security

Secure session management with automatic timeouts, IP-based session validation, and brute-force protection with account lockout after failed login attempts.

HTTPS/TLS Encryption

HTTPS-only connections with HSTS enforcement. Security headers configured via Helmet.js (CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy).

Infrastructure

MicHelper uses a protected cloud environment for application services, persistent storage and encrypted backups. Approved AI services process requests under contractual privacy and retention controls; specific provider routing is confidential technical information.

Input Validation & Injection Prevention

Parameterized SQL queries prevent injection attacks. XSS pattern detection on input. File upload validation with type and size limits.

Data Isolation

Each customer network is logically isolated. Cross-tenant access is architecturally prevented.

Authentication & Access Control

Data Protection

Infrastructure Security

Audit & Monitoring

Data Lifecycle

Data TypeRetentionEncryption
Raw audioSuccessful transcription: deleted after completion; failed transcription: retry copy for up to 6 hoursTLS in transit (transient processing)
TranscriptsPersist during subscriptionAES-256-GCM field-level
Analytics & scoresPersist during subscription + 30 daysDatabase-level
Account dataSubscription + 30 daysAES-256-GCM for sensitive fields
Audit logs90 daysDatabase-level

Privacy & Compliance

Designed for the current Ukrainian market with data minimisation, purpose limitation, controlled access and human review in mind.

Privacy by Design

Built around data minimisation, purpose limitation, controlled retention and access-management practices.

Data Processing Agreement

Standard DPA available for all customers. We act as a processor on your behalf.

Privacy Requests

In-app tools for data export and deletion requests. Respond to data subject requests efficiently.

Breach Notification

Documented incident response procedures. Notification within 72 hours as required by applicable law.

Data Lifecycle & Retention

Audio Recordings

Audio is retained only until automatic transcription completes and is permanently deleted after successful transcription. This normally takes no more than 5 minutes. If transcription fails, a technical copy may be retained for up to 6 hours for an automatic retry and is then deleted.

Transcripts

Text transcripts generated from audio recordings persist during your subscription. Transcripts are a core service feature used for analytics, coaching, and reporting. Transcripts are encrypted at rest using AES-256-GCM field-level encryption.

Analytics, Scores & Performance Data

QA scores, coaching notes, event timelines, and metadata persist during your subscription plus 30 days after termination, to allow for data export. This data represents computed metrics and does not contain raw audio. Customers may request deletion through the account deletion process.

Account & Configuration Data

User accounts, network configurations, scripts, and system settings are retained for the duration of the active subscription and for 30 days following account termination to allow for data export.

Summary

Data Type Retention Encryption
Raw audio recordingsDeleted after successful transcription; failed-transcription retry copy limited to 6 hours[TODO: verify storage encryption for temporary audio in the production hosting configuration]
TranscriptsPersist during subscriptionAES-256-GCM field-level
Analytics & scoresPersist during subscription + 30 daysDatabase-level encryption
Account dataDuration of subscription + 30 daysAES-256-GCM for sensitive fields
Audit logs90 daysDatabase-level encryption
🔒
TLS 1.2+ Transport Security
🗄️
AES-256 At-Rest Encryption
📊
SOC 2 Protected cloud infrastructure
🛡️
Privacy by Design Privacy by Design

Security Commitment & Limitations

MicHelper implements industry-standard security measures to protect your data, including but not limited to:

No Absolute Guarantee. While we employ robust, multi-layered security controls and follow industry best practices, no system connected to the internet can guarantee 100% security. We commit to:

If you discover a potential security vulnerability, please report it responsibly to security@michelper.com. Do not access other users' data or publish technical details before we can investigate.

Vulnerability Disclosure

We value the security research community and welcome responsible disclosure of security vulnerabilities.

Please do not access or modify other users' data, disrupt services, or publicly disclose vulnerabilities before we have had a reasonable opportunity to address them.

Questions About Security?

Our team is happy to discuss your specific security and compliance requirements.