MIROR

Security at Miror

Your data is protected with privacy-first architecture, access controls and user-controlled access.

This page is maintained by Miror to answer common security questions about the Miror service. It describes the security practices that apply to the application as currently configured.

Security Principles

Miror is built around these core principles:

  • Privacy by Design
  • Least Privilege Access
  • User Ownership of Data
  • Permission-based Integrations
  • Secure by Default

Authentication & Connected Accounts

Users explicitly authorize every connected account through OAuth or the provider's secure authorization mechanism. Connected services may include:

  • Google Workspace
  • Microsoft 365
  • Slack
  • GitHub
  • Dropbox
  • Notion
  • WhatsApp
  • Other supported services

Miror never requests permissions beyond those required for enabled features.

Access Controls

  • Internal access is restricted.
  • Access follows least privilege.
  • Administrative access is logged and controlled.
  • User data is isolated between accounts.

Data Storage

Miror stores only the information necessary to provide requested functionality. Users remain in control of their connected accounts.

User Controls

Users can:

  • Connect accounts
  • Disconnect accounts
  • Revoke permissions
  • Delete memories
  • Delete workflows
  • Delete their Miror account
  • Request deletion of stored data

Responsible AI Security

  • AI only operates on data users have authorized.
  • AI never gains access to services that users have not connected.

Compliance

Miror is designed to comply with applicable privacy regulations and platform requirements, including:

  • Google API Services User Data Policy
  • Google Limited Use Requirements
  • DPDP (India)
  • GDPR where applicable