
Security at Miror
Your data is protected with privacy-first architecture, access controls and user-controlled access.
This page is maintained by Miror to answer common security questions about the Miror service. It describes the security practices that apply to the application as currently configured.
Security Principles
Miror is built around these core principles:
- Privacy by Design
- Least Privilege Access
- User Ownership of Data
- Permission-based Integrations
- Secure by Default
Authentication & Connected Accounts
Users explicitly authorize every connected account through OAuth or the provider's secure authorization mechanism. Connected services may include:
- Google Workspace
- Microsoft 365
- Slack
- GitHub
- Dropbox
- Notion
- Other supported services
Miror never requests permissions beyond those required for enabled features.
Access Controls
- Internal access is restricted.
- Access follows least privilege.
- Administrative access is logged and controlled.
- User data is isolated between accounts.
Data Storage
Miror stores only the information necessary to provide requested functionality. Users remain in control of their connected accounts.
User Controls
Users can:
- Connect accounts
- Disconnect accounts
- Revoke permissions
- Delete memories
- Delete workflows
- Delete their Miror account
- Request deletion of stored data
Responsible AI Security
- AI only operates on data users have authorized.
- AI never gains access to services that users have not connected.
Compliance
Miror is designed to comply with applicable privacy regulations and platform requirements, including:
- Google API Services User Data Policy
- Google Limited Use Requirements
- DPDP (India)
- GDPR where applicable
