Your data is isolated
Every Migna customer runs on a separate database and a separate deployment. Your records are never pooled with another company’s, there is no shared multi-tenant datastore, and there is no query anyone could write that would return your data and someone else’s together. A problem affecting one customer’s instance does not reach yours.
Where it lives
Every processor is listed in the sub-processor table below and in the Data Processing Agreement. Before adding or replacing one we give you notice at least 15 days in advance where practicable, and you may object within 15 days, as section 4.2 of the DPA sets out.
How it is protected
In transit and at rest
All traffic uses HTTPS with TLS, and database connections require TLS. Data at rest is encrypted by the hosting and database providers. Passwords are stored as salted scrypt hashes: never in plain text, and not recoverable by us.
Access control
Role-based permissions in three tiers. A user files and updates records. An admin additionally manages users, company settings, bulk import and export, deletion of records and corrections to historical records. A Super Admin controls what we operate on your behalf. Sessions use signed, HTTP-only, expiring cookies. Migna staff access to production is least-privilege.
Two-factor authentication
Every account can add a second factor: a six-digit code from an authenticator app, asked for after the password. An admin can require it for everyone at the company, in which case anyone without it is walked through setup at their next sign-in and nobody can turn theirs off. Recovery codes cover a lost phone, and an admin can reset a locked-out account. The authenticator secret is encrypted at rest with a key the database alone does not hold.
Record integrity
Closed incident reports are locked from editing. Recordable and severe incidents can only be changed by an administrator. An audit log records who changed what, and when.
Application hardening
A Content-Security-Policy and the standard security headers on every page. Rate limiting on login and on the AI endpoints. Validation and size limits on uploads. Exported CSVs are neutralised against spreadsheet formula injection, so text submitted through a public QR form cannot execute when an administrator opens the export in Excel.
API keys
The REST API only reads records; a key an admin gives the webhooks permission can also manage its own webhook subscriptions. An admin creates each key, chooses the kinds of records it may read and when it expires, and can revoke it at once. We store only a SHA-256 fingerprint of a key, never the key itself, so it is shown once when it is made and cannot be recovered from our side. Keys are limited to 120 requests a minute. The API never returns files, photos, signatures, contact details or anything medical, and a privacy case comes back without the person's name. Creating and revoking keys is recorded in the activity log.
Webhooks
An admin chooses where webhooks go and which events they carry. Every delivery is signed with HMAC-SHA256 and a timestamp using a secret only the admin's receiver and we hold; the secret is stored encrypted and can be rotated at any time. We send only to HTTPS addresses on the public internet, check where the address resolves before each delivery and refuse private networks, and never follow redirects. A webhook carries the same fields as the REST API, so no files, photos, contact details or anything medical. A subscription made by an integration with an API key covers only records that key can read, stops when the key is revoked or expires, and is listed on the admin's Webhooks page, where it can be turned off or deleted.
AI and untrusted input
The AI features read records that include free text submitted from site QR codes without a login. That content is delimited and labelled as data in every prompt, and the models are instructed not to act on instructions found inside it. Prompt injection has no complete defence, so the system is built so a successful attempt is bounded: the assistant's tools only read, and a change it prepares (a new corrective action, an update to one, or a safety observation) is shown on a card and saved only when the person who asked presses Confirm, once, under their own account; it cannot delete anything. Replies render as plain text rather than markup or links, and AI output is labelled as a draft for human review wherever it appears. Public QR pages accept submissions only and never expose your records, and per-site codes can be rotated.
Availability and recovery
Point-in-time recovery is enabled on your database. Uptime and application errors are monitored. We don’t publish a public uptime percentage; contractual availability commitments are in your Order Form, and our support commitments are in the support policy.
Sensitive employee information
Migna holds injury and illness details, including body part, injury type and days away. We treat this as sensitive:
- OSHA privacy-case handling is supported on the 300 log.
- Access follows the same role controls as the rest of your data.
- Bulk export is administrator-only.
Your data stays yours
- Export anytime. Every module exports to CSV, and a complete export of every record is available to your administrators in one click.
- Deletion on termination. When your subscription ends, your data stays available for export for thirty days, then we delete it, except where the law requires retention. The terms are in the Data Processing Agreement, not left to goodwill.
- We do not sell your data or use it to train AI models, and neither do the AI providers we send it to. Anthropic and OpenAI do not train on inputs sent through their APIs under their commercial terms, and every request we send to Deepgram opts out of its model-improvement program.
Sub-processors
Who touches your data, for what, and where. This table mirrors Annex III of the Data Processing Agreement.
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel | Application hosting | United States |
| Vercel Blob | File storage for uploaded documents, photos and evidence files | United States |
| Neon | Database hosting and storage | United States |
| Anthropic | AI features, only when the AI add-on is enabled. Inputs are not used to train models. | United States |
| Resend | Transactional and notification email | United States |
| Twilio | SMS alerts, only when the SMS add-on is enabled | United States |
| OpenAI or Deepgram | Speech-to-text for voice notes, whichever one is configured, only when the AI add-on is enabled | United States |
| Open-Meteo | Weather data, using job-site coordinates only | EU / US |
| U.S. National Weather Service | Severe-weather alerts, using job-site coordinates only | United States |
| Sentry | Error monitoring: the page, the technical error and the signed-in account identifier | United States |
| RainViewer | Weather radar tiles: the device IP and the map area being viewed, never safety records | EU |
| OpenStreetMap | Map tiles and address lookup: the device IP and the coordinates or address text, never safety records | UK / EU |
What we do not have yet
We would rather tell you than let you assume.
- No SOC 2 or ISO 27001 certification. Migna is a small, focused company. We compensate with single-tenant isolation and a deliberately small data footprint, and we will say so plainly in any security questionnaire.
- No third-party penetration test to date.
If any of these is a requirement for your organisation, tell us. We would rather know early than surprise you at signature.
About the public demo
The live demo is a separate installation with its own database, holding generated sample data only. It processes no customer data and is out of scope of the Data Processing Agreement. Visitors share one limited account, the instance is wiped and reseeded daily, and anything a visitor enters is visible to other visitors until then. A banner on every screen of the demo, printable views included, says so.
The documents
Questions, or a security questionnaire to fill in: info@mignasafetysolutions.com. You will get a person who knows the system.