ManaMD
Trust

Security & data handling

Security reviews in medical devices usually start with one question: where is the patient data? Our answer shortens the conversation considerably.

No patient data, by design

ManaMD contains no patient records, no PHI, and no claims-level detail about individuals. The market data in the app is aggregate, provider-level information published by federal agencies: CMS, NPPES, openFDA, and ClinicalTrials.gov. There is no patient data to breach because none is collected, stored, or transmitted, and the product is deliberately built so that stays true. Because no PHI is involved, no business associate agreement (BAA) is required.

Your working data is protected

Visit logs, notes, follow-ups, and account statuses are stored on the rep's iPhone or iPad, protected by iOS's built-in encryption at rest and the device passcode. The app is built offline-first: a rep's day never depends on a signal, and any data that moves does so over encrypted connections, scoped to your organization.

Data in transit

All network traffic, data updates and AI requests alike, travels over TLS-encrypted connections. AI requests are processed by Anthropic under API terms that exclude them from model training.

Distribution and platform

The app is built for iPhone and iPad, and every build passes Apple's review and code-signing chain before it reaches a device. The website is statically hosted with no server-side code and no database of its own.

What we don't claim

We are a young company and we say plainly what we have and haven't done: we do not yet hold formal certifications such as SOC 2. What we offer instead is a materially smaller attack surface, with no patient data anywhere in the system, and straight answers to security questionnaires. If your evaluation requires specifics, ask through the support page and you will get them.

Reporting a vulnerability

If you believe you have found a security issue in the app or this site, contact us through the support page with enough detail to reproduce it. We will acknowledge the report promptly, and we will not pursue good-faith research.