SECURITY · DATA HANDLING · COMPLIANCE

Your business is yours.

You're handing Mijoro the most sensitive material your company produces — your board decks, your financials, your strategy, your unfair-advantages. Below is exactly what we do with it, exactly what we don't, and exactly how we prove it. No vague promises. No "industry-standard" hand-waving.

Encrypted everywhere
At rest. In transit. At sleep.
Zero training on your data
Yours stays yours. Always.
Every claim, traceable
Click → source. Always.
Tamper-proof exports
Merkle-tree audit trail.
Factory reset wipes it all
One button. We mean it.
01 · DATA LIFECYCLE

Exactly where your data goes — and exactly where it doesn't.

01
UPLOAD

Every file you upload arrives over TLS 1.3 and is encrypted at rest with AES-256 the moment it lands. The plaintext exists for the milliseconds the platform needs to extract content.

02
PROCESS

Mijoro reads, embeds, and writes against a per-tenant logical partition. No shared keyspace. No cross-customer index. No tenant ever queries data they don't own.

03
STORE

Postgres in the region you choose, behind a private network. Daily encrypted backups. Point-in-time recovery. No data ever leaves your region without your explicit consent.

04
DELIVER

Reports leave the platform signed (Merkle-tree audit trail), encrypted in transit, and delivered to recipients you specify. Share links are token-protected, expire by default, and revocable in one click.

05
FORGET

Factory reset wipes every file, every derived artifact, every backup row, every embedding. The account skeleton stays. Everything we ever produced for you is gone within fifteen minutes.

02 · CORE GUARANTEES

Eight things we promise. And the way we prove each one.

DATA · STORAGE

Encrypted, isolated, regional.

Every file, every conversation, every artifact lives in an encrypted database in a region you control. At rest, in transit, and at sleep — encryption is non-optional. Per-tenant logical isolation; no shared keyspace; no cross-customer leakage paths.

PROOF · AES-256-GCM at rest · TLS 1.3 in transit · per-tenant row policy
DATA · TRAINING

We don't train on your content.

Your files, your numbers, your interview answers — none of it is used to train AI models. Your strategic context is yours. It's used to write your reports. That's the entire contract.

PROOF · Contractual zero-retention with reasoning subprocessor · No fine-tuning pipeline · Auditable in our DPA
PROVENANCE

Every claim, traceable.

Every sentence Mijoro writes can be traced back to the file, the conversation, or the data point that produced it. Click any claim and the platform shows you exactly where it came from. Nothing fabricated. Nothing unverifiable.

PROOF · Citation pins on every claim · Source-row hash in every report
AUDIT TRAIL

Tamper-proof signatures.

Every report Mijoro produces ships with a cryptographic hash. You can verify later — at any time — that the report you signed off on hasn't been edited since. The audit trail is a Merkle tree over every stage of every artifact.

PROOF · SHA-256 leaf hashes · Merkle root in every export · Verifiable via /audit endpoint
ACCESS

Sessions you can revoke.

Argon2id-hashed passwords. Session tokens stored only as hashes server-side. Password reset rotates every active session in one move — if you suspect anything, you can lock out every device on the account in seconds.

PROOF · Argon2id (m=64MB, t=3, p=2) · Server-side token hashes · One-click global session reset
DELETE

One button. We mean it.

Factory reset wipes everything we ever produced for you — every run, every dossier, every uploaded file, every conversation, every embedding. One confirmation phrase, one click. Account row stays; everything else is gone in under fifteen minutes including backups.

PROOF · Cascade delete across 47 tables · Backup-aware purge · Confirmation receipt on completion
COMPLIANCE

Built for serious operators.

Architecture mapped to SOC 2 Type II controls; certification in progress. GDPR-ready data handling, including data-subject-access and right-to-be-forgotten flows. Per-region data residency available on Enterprise and Boardroom tiers.

PROOF · SOC 2 Type II controls matrix · GDPR Art. 15-22 endpoints · DPA available on request
EMAIL & SHARING

Locked-down deliverables.

Outbound email runs through audited transactional infrastructure. Public share links are token-protected, expire by default (24 hours unless extended), view-count cappable, and revocable in one click. Recipients are recorded; surprise is impossible.

PROOF · Per-link rotating token · Recipient hash log · Revocation propagates within seconds
03 · COMPLIANCE POSTURE

Where we are on every control framework that matters.

IN PROGRESS
SOC 2 TYPE II
Controls implemented; observation window in motion. Audit report Q4 2026.
READY
GDPR
Data-subject-access, portability, erasure, and rectification endpoints live.
READY
CCPA / CPRA
"Do not sell" and deletion rights honored out of the box. Annual privacy assessment.
AVAILABLE
DPA · MSA · BAA
Data Processing Addendum and Mutual Service Agreement on request. BAA available for HIPAA workloads on Enterprise+.
AVAILABLE
PEN TEST & SBOM
Quarterly third-party penetration test report. Software bill of materials on request.
READY
REGION RESIDENCY
US, EU, UK on request. Region is enforced at the database layer, not just routing.
04 · SUBPROCESSORS

The short list of vendors your data ever touches.

We keep this list small on purpose. Every subprocessor is contracted to zero-retention or short-retention windows. None of them are permitted to train on customer content.

SUBPROCESSOR
PURPOSE
DATA TYPE
RETENTION
Cloud infrastructure provider
Hosting, storage, networking
All platform data (encrypted)
Lifetime of contract
Reasoning subprocessor (undisclosed)
Language reasoning calls
Per-request prompts only
Zero retention
Transactional email provider
Outbound report delivery
Recipient + subject only
30 days
Payment processor
Subscription billing
Billing identity only (no platform data)
Per regulatory requirement
Error / performance monitoring
Production observability
Stack traces (PII-stripped)
30 days

Subprocessor list is binding. We give thirty days' notice before adding any new vendor that touches customer data. Subscribe to the subprocessor change log →

05 · RESPONSIBLE DISCLOSURE

If you find a security issue, tell us first.

We run a private vulnerability disclosure program. Email security@mijoro.com with reproduction steps. We acknowledge within one business day, triage within three, and credit reporters on resolved findings (unless you prefer anonymity).

  • Acknowledge: ≤ 24 business hours
  • Initial triage: ≤ 72 hours
  • Fix-or-mitigation ETA: communicated within 5 business days
  • Public disclosure: coordinated, never before users are protected
RESPONSIBLE DISCLOSURE INBOX
security@mijoro.com
Bug bounties are offered case-by-case at our discretion. We acknowledge every report.
99.9%
UPTIME TARGET (ENTERPRISE+)
Measured monthly. Credits issued automatically on miss.
≤ 4 hrs
RPO · POINT-IN-TIME RECOVERY
Encrypted backups every four hours, retained per region policy.
≤ 1 hr
RTO · RECOVERY TIME OBJECTIVE
Tested quarterly in non-production environments.
24/7
INCIDENT MONITORING
Paged on automated anomaly detection and on customer reports.

If you have any security question, ask.

Email security@mijoro.com for security questions, data processing agreements, vendor reviews, penetration test reports, or anything else you'd ask before handing a platform your most sensitive material. We answer within one business day.