Security

Updated July 10, 2026

In transit

All traffic to Melric runs over HTTPS with TLS. There is no unencrypted path to the service.

Your account

Passwords are stored hashed, never in plain text. Sign in with your Google or Microsoft account if you prefer. Logins are rate limited, and sessions are hardened against forgery and fixation.

Isolation

Every customer workspace is sealed from every other. Access is deny-by-default: a capability that has not been explicitly granted does not exist for that account, and failures close doors rather than open them.

You hold the trigger

Melric drafts, stages, and prepares. Nothing sends, posts, or spends without a human approving it. That is a design rule, not a setting.

Your data

We do not sell your data and we do not run ads. The providers that host and power Melric are bound to use your content only to provide the service. We do not use your content to train AI models.

Backups

Business data is backed up on a recurring schedule with versioned history, encrypted copies stored off-site, and point-in-time snapshots for fast recovery.

Found something?

If you believe you have found a vulnerability, email [email protected]. We read every report, and we will not pursue good-faith research conducted without harming user data or service availability.