Your data is yours. We protect it like it is.
Michi is built for founders who sell to hospitals, governments and enterprises, and those customers ask about your security posture before they sign. Here is exactly how we protect your pipeline data.
Seven things we do, and what each one actually means.
01
Row-level security
Every database table has PostgreSQL Row-Level Security enabled, so queries are enforced at the storage layer rather than only in application code. Each user can read and write only rows belonging to their own organisation: even if a bug existed in the API layer, the database itself would reject the query. Policies are version-controlled in our migration files and reviewed on every pull request.
02
Encrypted tokens and credentials
Team invite tokens are cryptographically random 32-byte values that expire after 7 days and are invalidated immediately on acceptance. OAuth tokens for Gmail and Outlook are encrypted at rest with AES-256-GCM, and the encryption key is stored in environment secrets rather than in the database. No secret is committed to source code.
03
EU data residency
All customer data is stored in the EU region of Supabase, in Frankfurt. The AI inference layer processes prompts and is not used to train models, and your pipeline data is not retained beyond the request. Email delivery, monitoring and analytics are all configured to EU endpoints.
04
GDPR by default
Full export is available at any time from Settings, and deleting your organisation removes its records after a 30 day grace period. Files in storage and your Stripe subscription are handled separately: contact us and we will complete those. A DPA is available on Pro and above. We collect only what the service needs, and we do not sell data.
05
Monitoring and incident response
Application errors and performance issues are captured in the EU region and P0 incidents alert the engineering team immediately. Stripe webhook events are deduplicated by event ID, so a billing event cannot be processed twice. Our uptime target is 99.9% monthly, excluding scheduled maintenance.
06
Audit log
On Team and Growth. Every data mutation, from record creation to a team invite, is written to an immutable table with the user, the timestamp, the action, the entity and a diff of what changed. Users cannot edit or delete entries. Logs are retained for 12 months and can be exported as CSV on request.
07
Infrastructure and deployment
The application runs on an edge network with automatic HTTPS and a global CDN. The database is managed Postgres with automated daily backups, retained 7 days on Pro and 30 on Team and Growth, with point-in-time recovery on request. Every change goes through pull request review and the main branch is protected.
Found something? Tell us.
We take security reports seriously and respond within 24 hours. Email security@michiplatform.com with a description and reproduction steps. We do not pursue legal action against good-faith researchers.
For general data protection enquiries, write to privacy@michiplatform.com.
The documents, and the detail behind them.
- Sub-processors: the 18 providers we use, with their regions and DPAs.
- Retention: how long we keep each kind of data, and what triggers deletion.
- Data Processing Agreement: the Article 28 terms and the binding sub-processor annex.
- Privacy policy, and the terms it sits under.