Security is part of the product boundary.
MIA is a multi-tenant hosted application. Every request for operational data resolves the caller's organization and site membership before it renders anything, and that boundary is exercised by an automated cross-tenant isolation test on every commit.
Controls in place today
- Transport. HTTPS with HSTS. Session cookies are HttpOnly, SameSite=Lax, and Secure in production.
- Passwords. PBKDF2-SHA256, 310,000 rounds, per-user random salt. Changing a password invalidates existing sessions.
- Sign-in. Five failed attempts on one account from one network address within fifteen minutes locks that pair out for fifteen more. Every attempt, successful or not, is recorded with its address, and cleared after 90 days.
- Authorization. Organization and site membership is checked on every protected route. Owner, admin, member and viewer are distinct: an administrator cannot grant themselves owner access, remove an owner, or reset an owner's password.
- Forms. CSRF tokens on every state-changing request.
- Browser headers. HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, COOP and CORP — asserted against the live site on every deploy, not only in the build.
- Hosting. Non-root application user, managed PostgreSQL.
- Audit. What was done in a workspace — access changes, removals, exports, deletions, validation verdicts, questions asked — is recorded with the acting user and their IP. An owner or administrator can retrieve their organization's trail from
/api/audit; the privacy notice says what it holds.
Reporting a vulnerability
Email security@miareliability.com, or see /.well-known/security.txt. Tell us what you found and how to reproduce it; we will acknowledge and keep you informed while we fix it.
Please test only against accounts and data you own. Do not run automated scanners against the hosted service, access another tenant's data, degrade availability for other users, or exfiltrate customer records — if you can demonstrate a boundary is crossable, stop there and tell us.
What we ask of you
Uploaded operational data is treated as customer-controlled maintenance information. It should not contain credentials, secrets, or personal data unrelated to maintenance work — see the privacy notice.
Beta status. This page describes controls that are actually in place, verified by the test suite and by a check against the running site. It is not a certification, an audit result, or a claim of compliance with a specific security framework.