MedQara
Security & Compliance

A platform designed for the European medical world

100% EU hosting, end-to-end encryption, full GDPR compliance and OWASP security headers. Here is how we protect your data and the trust of QA/RA professionals.

100% European hosting

All data is hosted in Germany (Frankfurt) on Render and Supabase. No structural transfer outside the EU.

  • Application: Render - Frankfurt (DE)
  • Database: Supabase - Frankfurt (DE)
  • CDN: Cloudflare - DPF certified (GDPR compliant)
  • Transactional emails: Resend - GDPR compliant

End-to-end encryption

TLS 1.3 for all exchanges, AES-256 for data at rest. Your data is never transmitted in clear text.

  • HTTPS enforced via HSTS (preloaded)
  • Automatically renewed TLS certificates
  • AES-256-GCM encryption of data at rest (Supabase)
  • Encrypted, geo-replicated backups

Reinforced authentication

Passwords stored as irreversible hashes. Cloudflare Turnstile CAPTCHA against automated attacks.

  • bcrypt hash on Supabase Auth (industry standard)
  • Cloudflare Turnstile CAPTCHA on signup
  • Mandatory email verification (PKCE flow)
  • Secure sessions (httpOnly cookies)

HTTP security headers

Complete OWASP header configuration to block XSS, clickjacking and MIME-sniffing.

  • Strict-Transport-Security (HSTS preload)
  • Strict Content-Security-Policy
  • X-Frame-Options: SAMEORIGIN
  • X-Content-Type-Options: nosniff
  • Restrictive Permissions-Policy
  • Referrer-Policy: strict-origin-when-cross-origin

Anti-DDoS & edge protection

Cloudflare at the front protects against volumetric and application-layer attacks.

  • Automatic L3/L4/L7 DDoS protection
  • Application-level rate limiting (1000 req/min)
  • Cloudflare Web Application Firewall (WAF)
  • Anonymous cookieless analytics

GDPR compliance

A platform designed for GDPR from the start. User rights are easily accessible.

  • Full hosting in the EU
  • Transparent privacy policy
  • Right of access, rectification, erasure
  • Data portability
  • No tracking cookies
  • Breach notification (Art. 33)

Important notice

MedQara is a monitoring support tool. AI analyses are indicative. For any regulatory decision, the user must always consult the referenced official source and, where appropriate, the opinion of a qualified QA/RA expert.

Report a vulnerability

If you discover a security flaw, contact us directly. We commit to responding within 48h and fixing critical issues quickly.

contact@veillemedqara.fr