Enterprise-Grade Trust

Security & Data Protection

We treat your client data with extreme care. Here is how we protect your schedule, customer information, and business records.

Data Encryption

All client data is encrypted in transit using TLS 1.3 and at rest using AES-256 standard encryption.

Row-Level Security (RLS)

Powered by Supabase RLS. Business data is strictly isolated so no account can ever access another tenant's records.

LemonSqueezy PCI Compliance

MileKit never stores or processes credit card credentials directly. Payments are handled via LemonSqueezy (PCI Level 1 certified Merchant of Record).

Rate Limiting & DDoS Defense

Protected by Upstash Redis edge rate-limiting to prevent brute force, spamming, or automated bot attacks.

Infrastructure & Cloud Security

MileKit is hosted on modern cloud infrastructure powered by Vercel and Supabase. Datacenters adhere to SOC 1, SOC 2, ISO 27001, and HIPAA compliance protocols. Daily database backups ensure high availability and zero data loss risk.


Client Privacy & Data Isolation

We never sell, rent, or trade your client records or contact lists to third-party advertisers. Your client phone numbers and email addresses are used exclusively for dispatching reminders, review requests, and recall notifications generated by your business.


Vulnerability Disclosure Protocol

If you believe you have discovered a potential security vulnerability in MileKit, please report it immediately to our security architecture team at support@milekit.com. We review all submissions within 24 hours.