SECURITY & DATA HANDLING

Security is part of the product boundary.

MIA is a multi-tenant hosted application. Every request for operational data resolves the caller's organization and site membership before it renders anything, and that boundary is exercised by an automated cross-tenant isolation test on every commit.

Controls in place today

Reporting a vulnerability

Email security@miareliability.com, or see /.well-known/security.txt. Tell us what you found and how to reproduce it; we will acknowledge and keep you informed while we fix it.

Please test only against accounts and data you own. Do not run automated scanners against the hosted service, access another tenant's data, degrade availability for other users, or exfiltrate customer records — if you can demonstrate a boundary is crossable, stop there and tell us.

What we ask of you

Uploaded operational data is treated as customer-controlled maintenance information. It should not contain credentials, secrets, or personal data unrelated to maintenance work — see the privacy notice.

Beta status. This page describes controls that are actually in place, verified by the test suite and by a check against the running site. It is not a certification, an audit result, or a claim of compliance with a specific security framework.