Security & trust

What we do, and what we don't have yet.

You're putting years of work and some genuinely personal writing into this product. You deserve a straight answer about how it's handled — including the parts where the honest answer is "not yet."

How your data is protected.

Access control at the data layer

Every applicant-owned record carries an owner, and the database itself enforces who can read or write it. Access isn't a check the interface performs and could forget — a query for someone else's data returns nothing, regardless of where it comes from.

Encrypted in transit and at rest

Traffic to MedPath is served over HTTPS, and stored data is encrypted at rest by our database and hosting providers.

Sharing is explicit and revocable

Nobody sees an applicant's data unless that applicant invites them. Invitations are scoped to specific areas of the application, the sensitive ones are off by default, and access can be revoked immediately.

We never hold portal credentials

MedPath does not store AMCAS, AACOMAS, or school portal passwords, and it never asks for them. Any message requesting them is not from us.

Payments stay with the processor

Card details are handled by our payment processor. We receive subscription status and billing metadata — never full card numbers.

Errors are monitored, essays aren't

We log application errors and product analytics so we can fix what's broken. Essay content is not part of that pipeline, and it isn't included in analytics.

AI boundaries

Where your writing goes.

The single most common question we get, answered without hedging.

  • Drafts go to our AI provider only when an applicant explicitly asks for feedback — nothing is sent in the background.
  • Applicant content is not used to train AI models, and our provider is contractually prohibited from training on it.
  • The advisor coaches and asks questions; it does not generate essay content for submission.
  • The advisor does not produce admissions probabilities or chance estimates.
Straight answer

What we don't have.

If a formal certification is a requirement for your office, we'd rather you know now than three meetings in.

  • We don't hold a SOC 2 report or an ISO 27001 certification today.
  • We don't offer SSO or institutional account provisioning yet.
  • We aren't a HIPAA-covered entity — MedPath is an application planning tool and isn't intended for protected health information.

Your controls.

Security isn't only about what we do — it's about what you can do without asking us.

Export your full application data at any time, in a portable format, from your account settings.

Delete your account yourself — no support ticket and no retention call. Deletion removes your application data from production promptly and from routine backups within 30 days.

Review and revoke advisor access whenever you want. Revocation takes effect immediately.

Found a vulnerability?

Report it to security@medpath.app and we'll acknowledge it quickly. Please give us reasonable time to fix an issue before disclosing it publicly, and don't access, modify, or retain other people's data while testing. We won't pursue legal action against researchers acting in good faith under those terms.