Indilum
← Back to Indilum

Security at Indilum

Last updated: April 2026 · Indilum is in beta. This page describes our actual security practices — not aspirations.

Plain-English summary

Indilum stores family medical records — lab PDFs, measurements, and notes. We take that seriously. Everything we store is encrypted, access is restricted, and you can export or delete your data any time from account settings. We are not yet HIPAA certified; if you are a healthcare provider looking to store patient PHI on our behalf, don't do that yet — we'll contact you when we are.

What we encrypt

Who can access your data

Subprocessors

We use the following third parties. Each one is covered in our Privacy Policy.

Data retention

What we don't do yet

We want to be straight with you. As of this writing, Indilum has not completed:

If you need any of these for your use case, we are not the right tool for you yet. These are on our roadmap.

Your controls

Reporting a vulnerability

If you believe you've found a security issue, please email security@indilum.health. We'll acknowledge within 2 business days and keep you updated until it's resolved. We don't run a paid bug bounty yet, but we credit reporters (with permission) on this page.

We ask that you don't access, modify, or destroy other users' data during testing, don't run automated scanners against production, and give us a reasonable window to fix issues before public disclosure.

Incident response

If we detect or are notified of a breach affecting your data, we will notify affected users by email within 72 hours of confirmation, and post a public incident report describing what happened, what data was involved, and what we've changed to prevent a recurrence.

Questions? Email security@indilum.health.

Security · Indilum