Security & compliance

Enterprise-grade controls, plainly stated.

Your account holds real work — pitches, financials, progress notes, personal reflection. Here is exactly how it is protected, and which frameworks we hold ourselves to.

The program

Nine controls we run continuously.

Identity & access

Every account is authenticated through a managed identity provider with email verification or Google sign-in. Sessions use short-lived, automatically rotated access tokens. Passwords are never stored by Melanin Valley — only salted hashes held by the identity provider.

Least privilege by default

Row-level security is enforced on every table holding member data, so a request can only ever read or write rows that belong to the signed-in account. Administrative surfaces are gated by a separate role table, never by a flag a client can edit.

Encryption everywhere

All traffic is served over TLS 1.2+ with HSTS. Data at rest is encrypted with AES-256. Secrets and API keys live in a managed secret store, are never checked into source, and are never exposed to browser code.

Application hardening

Server endpoints validate every input, enforce CSRF protection on state-changing calls, and rate-limit AI and media endpoints per client to blunt abuse and credential stuffing.

Continuous monitoring

Automated security scans run against the database policy set and the dependency tree on every change. Findings are triaged before release, and unresolved high-severity findings block a deploy.

Vendor & subprocessor review

Every third-party processor — hosting, database, AI model gateway, email, commerce — is reviewed for its own security posture and data handling before it touches member data, and re-reviewed when scope changes.

Logging & audit trail

Authentication events, administrative actions, moderation decisions, and consent records are logged with timestamps so any access to member data can be reconstructed after the fact.

Incident response

We maintain a written incident response plan with defined severity levels, an on-call owner, containment and forensics steps, and notification to affected members without undue delay.

Business continuity

Databases are backed up continuously with point-in-time recovery. Restores are tested, and infrastructure is defined in code so the platform can be rebuilt from a known-good state.

Data pledge

No selling. No sharing. No leaking.

Four promises that govern every table, endpoint, and model call on this platform.

No selling. Ever.

We do not sell, rent, or license member data to anyone, for any price. There is no data broker relationship, no advertising exchange, and no revenue line anywhere in this business that depends on your information.

No sharing without you

Nothing leaves your account unless you send it. Progress notes are visible only to you until you create a share link yourself — and that link carries an expiry, an optional view limit, only the sections you picked, and a revoke button.

No training on your work

Your conversations, pitches, and progress notes are never used to train external models. AI requests are sent for a single response and are not retained by the model provider for training.

Minimum necessary access

Choreographers see only work notes for a connection they are actively part of. Administrators see a note only when an open dispute is attached to it. Nobody at Melanin Valley browses member records casually — and every access is logged.

Encryption

How your data is actually protected.

In transit

Every request runs over TLS 1.3 (1.2 minimum) with modern cipher suites, HSTS, and certificate rotation handled by our edge provider. There is no plaintext path into the platform.

At rest

Databases, backups, and uploaded media are encrypted with AES-256. Storage buckets are private by default and served only through short-lived signed URLs, never public paths.

Keys & secrets

API keys and service credentials live in a managed secret store with restricted access, are never committed to source, and are never shipped to browser code. Privileged database credentials are unavailable even to the application layer.

Sessions & tokens

Short-lived, automatically rotated access tokens with server-side verification on every protected call. Share tokens are high-entropy, single-purpose, expiring, and revocable.

Abuse resistance

Per-client rate limiting on AI, voice, and media endpoints; input validation on every server call; and continuous automated scanning of database access rules and dependencies.

Managed keys & rotation

All data at rest is encrypted under keys held in a managed key management service, with provider-managed rotation and no key material ever present in application code, logs, or browser bundles. Integration secrets live in the same managed store, are scoped to a single purpose, and are readable only by server-side code.

Data-loss prevention

Exports and downloads are counted per account per hour. Unusual volume raises an alert you can see in your Data Rights Center; excessive volume is blocked outright until you confirm it was you. Every access, export, and share is written to an append-only log that nobody — including us — can edit or delete.

Honest comparison

Messaging apps like Signal or WhatsApp use end-to-end encryption, where the server cannot read content. Melanin Valley needs to read your notes to generate summaries, search, and AI support, so we use strong encryption in transit and at rest plus strict access control and audit logging — and we say so plainly rather than borrowing a term that would not be accurate.

Frameworks

What we are measured against.

We name our status honestly — aligned, implemented, or in progress. No badge we haven't earned.

  1. 01

    HIPAA-aligned safeguards

    Melanin Valley is not a healthcare provider, insurer, or clearinghouse, so it is not a HIPAA covered entity — and Selam is a supportive guide, not a therapist. Even so, progress notes and wellbeing reflections are handled with HIPAA's Security Rule safeguards as our design baseline: unique user identification, automatic session expiry, encryption in transit and at rest, role-based minimum-necessary access, immutable audit logging of every read, edit, export and share, and time-limited, revocable disclosure links. If we ever operate under a covered arrangement, we will execute a Business Associate Agreement before any protected health information is handled.

  2. 02

    SOC 2 Trust Services Criteria

    Our controls are mapped to the Security, Availability, and Confidentiality criteria. Formal audit and attestation are in progress; we do not claim a completed report until one is issued.

  3. 03

    GDPR & UK GDPR

    Lawful basis, consent records, data subject rights, and processor agreements are implemented for members in the EU and UK.

  4. 04

    CCPA / CPRA

    California members can access, correct, delete, and opt out of sale or sharing. We do not sell personal information.

  5. 05

    OWASP ASVS

    Application controls are built against the OWASP Application Security Verification Standard and the OWASP Top 10.

Your rights

Controls you hold, not us.

Access & export

Download a complete machine-readable copy of your profile, conversations, and stored AI memory from your account page at any time.

Correction

Edit your profile, nickname, location, and what you're building directly — changes take effect immediately across Sean, Selam, and the Work hub.

Erasure

Erase what the AI remembers with one click, or ask us to delete your account entirely. Deletion cascades to conversations, memory, and work records.

Opt-in improvement only

Your content is not sold and is not used to train external models. Anything used to improve Melanin Valley is opt-in and revocable.

Exercise any of these in one click from your Data Rights Center— including consent switches, a full export, erasure, a HIPAA Business Associate Agreement request, and a definitive answer on whether your data was ever shared.

To report a vulnerability or request a security review, reach us through the contact channels on the About page. We acknowledge reports within two business days and never pursue good-faith researchers.

Create your account.

Individualized AI support, saved work, and privacy controls that are actually yours.