How Medina19 protects your work.
Medina19 is an early-stage product. See how accounts, data, decisions, availability, and customer records are handled.
Check status Report a security issue
Current-release evidence matters. A control is not described as verified until it has been tested against the exact deployed release. An older deployment does not automatically verify a newer release. See Status for the running service.
Status labels
Core protections
| Area | Status | What Medina19 protects |
|---|---|---|
| Accounts and workspace access | Built, proof pending | Secure sessions, password protection, account recovery, role checks, rate limits, and separation between customer workspaces. |
| Human approval | Built, proof pending | Recommendations remain separate from approval. Implementation and external actions require authorized human decisions. |
| Data storage and recovery | Built, proof pending | Customer records, backups, restore procedures, change history, export, and deletion workflows. |
| Website and service reliability | Built, proof pending | HTTPS, security headers, health checks, monitoring, maintenance behavior, deployment identity, and rollback controls. |
| Evidence and outcomes | Built, proof pending | Sources, assumptions, estimates, approvals, observations, and confirmed outcomes remain clearly separated. |
| Payments and email delivery | Provider-dependent | These features require approved provider accounts, configuration, testing, and owner authorization. Creating a workspace does not create a charge. |
| External AI and external actions | Disabled by default | External processing requires consent and server approval. Sending, spending, publishing, and system changes require separate authorization. |
Use summarized, non-sensitive information
Do not submit passwords, API keys, payment credentials, regulated records, personal identifiers, confidential customer content, production secrets, or information you are not authorized to use.
Real customer data, system access, integrations, or production records require a separate signed agreement that defines purpose, access, approved providers, security, retention, export, deletion, incident handling, and termination. See the Privacy Policy.
People remain responsible for consequential decisions
Medina19 can organize evidence and recommend actions. It does not independently approve implementation, authorize spending, publish externally, change a customer system, or confirm a financial result.
Starting a review
Creating a workspace is free and creates no charge, contract, system-access authority, implementation authority, or guaranteed outcome. Paid work requires a separate signed agreement. See the Terms.
Report a concern
Use Help for account, privacy, or product questions. Follow security reporting instructions for a suspected vulnerability. Do not include secrets or sensitive customer content in the initial report.