Your data is yours.
We protect it like it is.

Michi is built for founders who sell to hospitals, governments, and enterprise — customers who will ask about your security posture before they sign. Here is exactly how we protect your pipeline data.

🔒 Row-level security on all tables🇪🇺 EU data residency (Frankfurt)🔑 Encrypted OAuth tokens at rest📋 GDPR compliant by design📊 Sentry monitoring (EU)🗂️ Immutable audit log (Team+)☁️ Vercel Edge + Supabase Postgres🔄 Daily automated backups
Row-Level Security (RLS)
Always on

Every database table has PostgreSQL Row-Level Security enabled. This means database queries are enforced at the storage layer — not just in application code.

Each user can only read and write rows that belong to their own organisation. Even if a bug existed in the API layer, the database itself would reject the query.

Policies are version-controlled in our migration files and reviewed on every pull request.

Encrypted tokens & credentials
AES-256

Team invite tokens are cryptographically random 32-byte values generated with Node's crypto.randomBytes. They expire after 7 days and are invalidated immediately on acceptance.

OAuth tokens for Gmail and Outlook integrations are encrypted at rest using AES-256-GCM before being stored in the database. The encryption key is stored separately in environment secrets, never in the database.

All secrets (Stripe keys, Resend API key, Supabase service role) are stored as Vercel environment variables — never committed to source code.

EU data residency
Frankfurt

All customer data is stored in Supabase's EU region (Frankfurt, Germany). No data transits to US-based storage.

The AI inference layer (Anthropic Claude) processes prompts but is not used to train models. Your pipeline data is never stored by Anthropic beyond the request lifetime.

Email delivery via Resend uses EU-compliant infrastructure. Monitoring via Sentry and analytics via PostHog are both configured to use EU endpoints.

GDPR compliance
DPA available

Michi is designed to be GDPR-compliant by default. You control your data: full export is available at any time from Settings, and account deletion removes all personal data within 30 days.

A Data Processing Agreement (DPA) is available on Pro and above. Contact us at privacy@michiplatform.com to request one.

We collect only the data required to operate the service. No selling of data, no ad tracking, no third-party analytics beyond what's disclosed in our privacy policy.

Monitoring & incident response
Sentry EU

All application errors and performance issues are captured by Sentry (EU region). P0 incidents trigger immediate alerts to the engineering team.

Stripe webhook events are deduplicated using a unique event ID stored in the database, preventing double-processing of billing events.

Uptime is monitored continuously. Our target is 99.9% monthly uptime excluding scheduled maintenance windows.

Audit log
Team & Growth

Available on Team and Growth plans. Every data mutation — record creation, update, deletion, team member invite — is written to an immutable audit_log table.

Each entry records the user, timestamp, action type, entity type and ID, and a diff of what changed. Logs cannot be edited or deleted by users.

Audit logs are retained for 12 months and can be exported as CSV on request.

Infrastructure & deployment
Vercel + Supabase

The application is deployed on Vercel's Edge Network with automatic HTTPS, DDoS protection, and global CDN.

The database is managed Postgres on Supabase with automated daily backups retained for 7 days (Pro) or 30 days (Team/Growth). Point-in-time recovery is available on request.

All code changes go through pull request review before deployment. The main branch is protected — no direct pushes.

Responsible disclosure

Found a vulnerability? We take security reports seriously and respond within 24 hours. Please email us at security@michiplatform.com with a description and reproduction steps. We do not pursue legal action against good-faith researchers.

For general data protection enquiries: privacy@michiplatform.com

Ready to get started?

Free plan, no credit card, data always exportable.

Create your account →
GDPR compliantEU data residencyCancel anytime14-day money backNo credit card