All MicHelper legal documents
Planned legal operator: TOV "MikHelper" (MicHelper LLC), Lviv, Ukraine. State registration is currently being completed. Official registration details will be published immediately after registration.
Security contact: security@michelper.com
Current market: MicHelper is preparing for launch in Ukraine.
🔐
Encryption in Transit
All connections to MicHelper use HTTPS with TLS 1.2 or higher. Data transmitted between your browser and our servers is always encrypted.
🔒
Encrypted Data at Rest
Sensitive data including transcripts and personal information is encrypted at rest using AES-256-GCM field-level encryption.
👥
Role-Based Access Control
Granular RBAC ensures users only see data relevant to their role. Sellers see their own data, managers see their teams, admins manage the network.
📋
Audit Logging
Actions are logged with timestamps, user IDs, and IP addresses. Full audit trail for compliance and security investigations.
⏱️
Rate Limiting
Global, per-user, and per-endpoint rate limiting protects against brute-force attacks and abuse. Suspicious activity is detected and blocked.
✅
CSRF Protection
All state-changing API endpoints are protected with CSRF tokens, preventing cross-site request forgery attacks.
Technical Security Measures
We implement multiple layers of protection to safeguard your data.
✓
Session Security
Secure session management with automatic timeouts, IP-based session validation, and brute-force protection with account lockout after failed login attempts.
✓
HTTPS/TLS Encryption
HTTPS-only connections with HSTS enforcement. Security headers configured via Helmet.js (CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy).
✓
Infrastructure
MicHelper uses a protected cloud environment for application services, persistent storage and encrypted backups. Approved AI services process requests under contractual privacy and retention controls; specific provider routing is confidential technical information.
✓
Input Validation & Injection Prevention
Parameterized SQL queries prevent injection attacks. XSS pattern detection on input. File upload validation with type and size limits.
✓
Data Isolation
Each customer network is logically isolated. Cross-tenant access is architecturally prevented.
Authentication & Access Control
- Secure session management with automatic timeout
- Sessions stored in database with IP and User-Agent tracking
- Brute-force protection: account lockout after 5 failed login attempts (15-minute cooldown)
- Per-IP and per-account rate limiting on login endpoints
- Role-based access control (RBAC) with 4 permission levels: seller, region_manager, network_manager, superadmin
- CSRF protection on all state-changing API endpoints
- Google OAuth support for single sign-on (optional)
Data Protection
- AES-256-GCM field-level encryption for sensitive data at rest (transcripts, personal information, notes)
- TLS 1.2 or higher for all data in transit
- Audio is deleted after successful transcription; a failed-transcription retry copy is limited to 6 hours
- Transcripts persist during subscription as a core service feature
- Bcrypt password hashing with salt
- Encryption keys managed via environment variables or secure persistent storage
Infrastructure Security
- Protected cloud environment for application services, persistent storage and encrypted backups
- MicHelper does not claim a product-level certification that it has not obtained
- Approved AI services operate under privacy and retention controls; specific provider routing is confidential
- Security headers via Helmet.js: CSP (with per-request nonce), HSTS, X-Frame-Options, X-Content-Type-Options, X-XSS-Protection
- Global rate limiting: 3000 requests/minute per IP (default; env-tunable)
- Auth rate limiting: 200 requests/minute per IP on /auth/* endpoints
- Upload rate limiting: 300 requests/minute per IP, 180 requests/minute per user (default; env-tunable)
- Beacon / emergency upload rate limiting: 20 requests/minute per IP
- File upload validation: type, size limits (up to 500 MB for audio, 25 MB for other endpoints), path traversal protection
- Parameterized SQL queries to prevent injection
- XSS pattern detection on input
- Automated encrypted database backups with rotation (last 10 retained; AES-256-GCM)
- Independent technical security reviews by multiple engineers (no formal penetration-test certification is claimed)
Audit & Monitoring
- Comprehensive audit logging of access, modifications, and security events
- Transcript access logging (who viewed what, when)
- Login attempt tracking with IP information
- Error and security incident logging with configurable retention
- Sensitive data redaction in logs
Data Lifecycle
| Data Type | Retention | Encryption |
| Raw audio | Successful transcription: deleted after completion; failed transcription: retry copy for up to 6 hours | TLS in transit (transient processing) |
| Transcripts | Persist during subscription | AES-256-GCM field-level |
| Analytics & scores | Persist during subscription + 30 days | Database-level |
| Account data | Subscription + 30 days | AES-256-GCM for sensitive fields |
| Audit logs | 90 days | Database-level |
Privacy & Compliance
Designed for the current Ukrainian market with data minimisation, purpose limitation, controlled access and human review in mind.
✓
Privacy by Design
Built around data minimisation, purpose limitation, controlled retention and access-management practices.
✓
Data Processing Agreement
Standard DPA available for all customers. We act as a processor on your behalf.
✓
Privacy Requests
In-app tools for data export and deletion requests. Respond to data subject requests efficiently.
✓
Breach Notification
Documented incident response procedures. Notification within 72 hours as required by applicable law.
Data Lifecycle & Retention
Audio Recordings
Audio is retained only until automatic transcription completes and is permanently deleted after successful transcription. This normally takes no more than 5 minutes. If transcription fails, a technical copy may be retained for up to 6 hours for an automatic retry and is then deleted.
Transcripts
Text transcripts generated from audio recordings persist during your subscription. Transcripts are a core service feature used for analytics, coaching, and reporting. Transcripts are encrypted at rest using AES-256-GCM field-level encryption.
Analytics, Scores & Performance Data
QA scores, coaching notes, event timelines, and metadata persist during your subscription plus 30 days after termination, to allow for data export. This data represents computed metrics and does not contain raw audio. Customers may request deletion through the account deletion process.
Account & Configuration Data
User accounts, network configurations, scripts, and system settings are retained for the duration of the active subscription and for 30 days following account termination to allow for data export.
Summary
| Data Type |
Retention |
Encryption |
| Raw audio recordings | Deleted after successful transcription; failed-transcription retry copy limited to 6 hours | [TODO: verify storage encryption for temporary audio in the production hosting configuration] |
| Transcripts | Persist during subscription | AES-256-GCM field-level |
| Analytics & scores | Persist during subscription + 30 days | Database-level encryption |
| Account data | Duration of subscription + 30 days | AES-256-GCM for sensitive fields |
| Audit logs | 90 days | Database-level encryption |
🔒
TLS 1.2+
Transport Security
🗄️
AES-256
At-Rest Encryption
📊
SOC 2
Protected cloud infrastructure
🛡️
Privacy by Design
Privacy by Design
Security Commitment & Limitations
MicHelper implements industry-standard security measures to protect your data, including but not limited to:
- HTTPS/TLS encryption for data in transit, AES-256-GCM for data at rest
- Deletion of raw audio after successful transcription, with a 6-hour maximum for failed-transcription retry copies
- Field-level encryption for sensitive data (transcripts, personal information)
- Secure password hashing (bcrypt with salt)
- Rate limiting and brute-force protection on all authentication endpoints
- CSRF protection on all state-changing operations
- Security headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options) via Helmet.js
- Role-based access control (RBAC) with principle of least privilege
- Automated data cleanup and retention enforcement
- Comprehensive audit logging of all access and modifications
No Absolute Guarantee. While we employ robust, multi-layered security controls and follow industry best practices, no system connected to the internet can guarantee 100% security. We commit to:
- Promptly investigating and addressing any security vulnerabilities discovered
- Notifying affected customers within 72 hours of confirming a data breach
- Continuously improving our security posture based on evolving threats
- Maintaining transparency about our security practices through this page
If you discover a potential security vulnerability, please report it responsibly to security@michelper.com. Do not access other users' data or publish technical details before we can investigate.
Vulnerability Disclosure
We value the security research community and welcome responsible disclosure of security vulnerabilities.
- Contact: security@michelper.com
- Response time: We will acknowledge receipt within 48 hours
- Scope: All MicHelper services at michelper.com
- Safe harbor: We will not pursue legal action against security researchers who follow responsible disclosure practices
Please do not access or modify other users' data, disrupt services, or publicly disclose vulnerabilities before we have had a reasonable opportunity to address them.
Questions About Security?
Our team is happy to discuss your specific security and compliance requirements.