Security
Security & Trust
Last updated: July 31, 2026
Our approach
MDI LABS is run by a security-minded team with enterprise hardening experience. Security isn't a feature we bolt on — it's how we operate.
What we secure
- Payments: processed entirely by Stripe (PCI-DSS Level 1). We never see or store card numbers.
- Data: encrypted in transit (TLS 1.2+) and at rest. Access limited to the people delivering your project.
- Deployments: SSH-key-only access, no password logins, least-privilege accounts.
- Credentials: never stored in plaintext; never committed to source control; rotated on request.
When we build for you
Deliverables ship with security basics included: updated dependencies, sanitized inputs, HTTPS enforcement, and a post-launch health check. Hardening packages are available for WordPress and custom sites.
Responsible disclosure
Found something on our site or infrastructure? Email hi@mdi.io with details. We respond within 48 hours and credit researchers who report responsibly.
Contact
Security questions: hi@mdi.io · San Diego, CA