Security status
Controls, evidence, and open gates.
Security claims stop where the evidence stops. This page separates implemented controls, internal tests, production canaries, and work that remains open.
Read current controlsDocumented controls
Each claim carries its evidence scope.
Accounts and sessions
The web gateway keeps the session credential in a secure, HTTP-only, same-site cookie. Sessions rotate, appear in account controls, and can be revoked. Account deletion revokes prior sessions before its receipt completes.
Archives and derived data
Current-candidate storage evidence is under review. MiMi does not claim end-to-end encryption.
Uploads and parsing
Uploads enter quarantine before parsing. The pipeline verifies size and hashes, scans for malware, rejects traversal, symbolic links, encrypted archives, expansion bombs, oversized members, and changed-after-scan objects. The pipeline is designed so a rejected object never enters product output.
Exports and deletion
Check account controls for the current export and deletion status.
Data Agent and connected services
MiMi does not receive passwords. Every provider action needs a separate disclosed mandate. Passwords, CAPTCHA, multi-factor authentication, identity documents, signatures, payments, legal attestations, changed actions, redirects, and missing confirmation stop for the person. Only eligible Gmail email requests whose exact contents you reviewed and that remain unchanged may be delivered. Official forms and non-Gmail routes remain Guided for you to complete.
Web application boundary
Current-candidate web response controls remain under review.
Evidence status
The current candidate still needs its own checks.
- The newest release candidate still needs its own browser lifecycle evidence.
- The newest release candidate still needs its own storage lifecycle evidence.
- Local security and integration suites exercise authentication, authorization, upload safety, retention, export, deletion, browser permissions, and provider fail-closed behavior.
- The repository history has been scanned for committed secrets. That check does not prove that an external system, account, or endpoint can never be compromised.
Open before M2
The newest candidate still needs its own proof.
- Named human security and operations owners must accept the exact release report and rollback plan.
- The exact final web and API candidate must pass staging, deployment, 30-minute canary hold, production lifecycle, and rollback checks.
- Real SMS, controlled email, and physical-device push delivery need provider receipts. Configuration or fixture delivery does not close those gates.
- Gmail metadata discovery is active. Microsoft mailbox discovery is not active.
- Official forms and non-Gmail routes remain Guided; reviewed Gmail email delivery stays bounded to unchanged, approved content.
Report a security issue
Send the minimum needed to investigate.
Email support@socialintelligencelabs.com with the subject “MiMi security report.” Include the affected surface, time, and steps to reproduce. Do not send passwords, login codes, archives, private keys, or another person's data. This channel does not offer a bug-bounty payment or safe-harbor promise.
Related controls