Security & Privacy

Your data security is our top priority. Learn how we protect your information.

Security First

Mikah is built with security at its core. We employ industry-standard encryption, secure authentication, and regular security audits to ensure your data remains protected at all times.

How We Protect Your Data

AES-256-GCM Encryption

All sensitive data is encrypted at rest using AES-256-GCM, the same standard used by banks and government agencies.

HTTPS Everywhere

All data in transit is encrypted with TLS 1.3. We enforce HTTPS on every connection with HSTS headers.

Secure OAuth

TikTok integration uses OAuth 2.0. We never see or store your TikTok password — only secure access tokens.

Password Hashing

User passwords are hashed using bcrypt with per-user salts. Even in the unlikely event of a breach, passwords remain protected.

Rate Limiting

API rate limiting protects against brute force attacks and abuse. Authentication endpoints have additional restrictions.

Security Headers

We implement comprehensive security headers including CSP, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy.

GDPR Compliance

Right to Access

Request a copy of all personal data we hold about you at any time.

Right to Deletion

Request complete deletion of your account and all associated data.

Data Portability

Export your data in a machine-readable format at any time.

Data Retention

Soft-deleted data is permanently removed from our systems after 90 days.

Payment Security

All payments are processed through Stripe, a PCI-DSS Level 1 certified payment processor — the highest level of certification available. We never store, process, or have access to your full credit card details.

PCI-DSS Level 1 certified
No card details stored on our servers
Encrypted payment processing

Report a Security Issue

Found a vulnerability? We take security reports seriously and will respond within 24 hours.