A platform designed for the European medical world
100% EU hosting, end-to-end encryption, full GDPR compliance and OWASP security headers. Here is how we protect your data and the trust of QA/RA professionals.
100% European hosting
All data is hosted in Germany (Frankfurt) on Render and Supabase. No structural transfer outside the EU.
- Application: Render - Frankfurt (DE)
- Database: Supabase - Frankfurt (DE)
- CDN: Cloudflare - DPF certified (GDPR compliant)
- Transactional emails: Resend - GDPR compliant
End-to-end encryption
TLS 1.3 for all exchanges, AES-256 for data at rest. Your data is never transmitted in clear text.
- HTTPS enforced via HSTS (preloaded)
- Automatically renewed TLS certificates
- AES-256-GCM encryption of data at rest (Supabase)
- Encrypted, geo-replicated backups
Reinforced authentication
Passwords stored as irreversible hashes. Cloudflare Turnstile CAPTCHA against automated attacks.
- bcrypt hash on Supabase Auth (industry standard)
- Cloudflare Turnstile CAPTCHA on signup
- Mandatory email verification (PKCE flow)
- Secure sessions (httpOnly cookies)
HTTP security headers
Complete OWASP header configuration to block XSS, clickjacking and MIME-sniffing.
- Strict-Transport-Security (HSTS preload)
- Strict Content-Security-Policy
- X-Frame-Options: SAMEORIGIN
- X-Content-Type-Options: nosniff
- Restrictive Permissions-Policy
- Referrer-Policy: strict-origin-when-cross-origin
Anti-DDoS & edge protection
Cloudflare at the front protects against volumetric and application-layer attacks.
- Automatic L3/L4/L7 DDoS protection
- Application-level rate limiting (1000 req/min)
- Cloudflare Web Application Firewall (WAF)
- Anonymous cookieless analytics
GDPR compliance
A platform designed for GDPR from the start. User rights are easily accessible.
- Full hosting in the EU
- Transparent privacy policy
- Right of access, rectification, erasure
- Data portability
- No tracking cookies
- Breach notification (Art. 33)
Important notice
MedQara is a monitoring support tool. AI analyses are indicative. For any regulatory decision, the user must always consult the referenced official source and, where appropriate, the opinion of a qualified QA/RA expert.
Report a vulnerability
If you discover a security flaw, contact us directly. We commit to responding within 48h and fixing critical issues quickly.
contact@veillemedqara.fr