Last updated: · Version: security-2026-09-25
Hosting
The app, API and database run on a server at Hostinger ({{VERIFY: data centre region}}). We don't run AI models ourselves. AI processing goes to the providers listed on our Subprocessors page.
Encryption
- All traffic to mielikkix.ai, app.mielikkix.ai and api.mielikkix.ai uses HTTPS (TLS), with HSTS enforced.
- Passwords are hashed with bcrypt and never stored in plain text.
- OAuth tokens for connected Google accounts are encrypted before storage, with a key held only on our servers.
- Disk and database encryption at rest: {{VERIFY: VPS disk / database encryption at rest}}.
Access control
- Each business can only reach its own data. Every API request is scoped to the signed-in business.
- Sessions use an httpOnly, SameSite cookie that page scripts can't read.
- Login and other sensitive endpoints are rate-limited.
- Only a small number of named staff can access the servers, using individual credentials {{VERIFY: SSH keys / 2FA}}.
Backups
{{VERIFY: backup frequency, location and retention}}
Incidents and breaches
If we detect a security incident, we contain it, assess the risk and document it. If personal data is affected, we notify Datatilsynet within 72 hours where required, and notify affected customers without undue delay so they can meet their own obligations.
Report a vulnerability
Found a security issue? Please email post@mielikkix.no and give us reasonable time to fix it before sharing it with others.