Trust Center

Security and compliance at MIOSA

MIOSA runs customer workloads on bare-metal servers in data centers we operate and manage ourselves. Every workload is isolated in its own machine, and a full set of controls protects it: MFA, SSO, RBAC, scoped keys, an audit log, egress controls and a secrets vault. MFA and SAML SSO are available today, and SAML SSO can be enforced per organization. This page is where enterprise buyers, security teams and their counsel can verify all of it.

Live status

Compliance

SOC 2 Type I Complete

Report available to customers and prospects under NDA.

SOC 2 Type II In progress

Observation window underway, with additional frameworks on our roadmap.

HIPAA Supported

HIPAA-compliant infrastructure for healthcare workloads. Business Associate Agreements available for Enterprise customers.

Who we work with

Enterprise

Dedicated capacity, SSO with SAML, role-based access, audit logging and documents under NDA for procurement and security reviews.

Fintech

Strong workload isolation, immutable audit trails and data residency you can point to in a vendor review.

Healthcare and medtech

HIPAA-compliant infrastructure, isolated per-workload machines and Business Associate Agreements on request.

Government and public sector

Private, dedicated deployments and self-operated data centers for teams that need control over where workloads run.

Infrastructure

Data centers we operate

MIOSA is not a reseller of a hyperscaler. We run our own bare-metal capacity in United States data centers that we provision, network and manage directly. That control is what lets us offer private and dedicated deployments.

Isolated machines, one kernel each

Every Sandbox, Computer and App Engine workload runs in its own machine with a dedicated kernel. Isolation is at the hardware boundary, so one workload cannot read another's memory, processes or disks.

Security controls

These ship enabled on every plan, with no add-on SKU. Each one is documented in depth in the security docs.

Per-workload machine isolation

Every Sandbox, Computer and deployed workload runs in its own machine with a dedicated kernel. Workloads never share memory, processes or a filesystem.

Multi-factor authentication

TOTP and email MFA on every account, with step-up verification for sensitive actions.

SAML single sign-on

SP-initiated SAML 2.0 SSO per organization, so your identity provider stays the source of truth.

Organization RBAC

Roles and scoped permissions per organization and workspace, enforced on every request.

Scoped API keys

Keys carry explicit scopes and a workspace binding. Revoke or rotate without touching the rest of your account.

Egress allowlist

Watch every outbound call in the audit log, then lock a workload down to an approved host list in one click.

Secrets vault

Keys stay encrypted at rest and reach the network boundary only. Sandboxes see opaque placeholders, never raw secret values.

Audit log

Every outbound call and privileged action is recorded, searchable and exportable by host, status and time.

Healthcare and HIPAA

MIOSA runs HIPAA-compliant infrastructure for healthcare and medtech customers. Protected health information is handled the same way as any other customer data: isolated, encrypted, access-controlled and logged. We sign a Business Associate Agreement with Enterprise customers on request.

  • Dedicated, isolated machine per workload, each with its own kernel.
  • Encryption in transit for all traffic, and encryption at rest for keys, secrets and environment values.
  • Access controls with MFA, SAML SSO and organization-scoped RBAC.
  • Audit logging of outbound calls and privileged actions.
  • Secrets are never exposed to the workload; sandboxes only ever see placeholders.
  • Egress controls to restrict what a workload can reach on the network.
  • Data stays in United States data centers we operate ourselves.
  • Business Associate Agreement available for Enterprise customers.

Data protection

Encryption

All traffic is encrypted in transit with TLS. Keys, secrets and environment values are encrypted at rest before they are written, using authenticated encryption.

Retention and deletion

You control the lifecycle of your data. Destroy a workload and its volumes are reclaimed; delete your account and personal data is removed in line with the Privacy Policy.

Backups

Managed Databases and platform state are backed up on a schedule and restore paths are exercised, so a failure does not become data loss.

Data location

Your workloads and data run in our United States data centers. Private and dedicated deployment models are available for teams with specific residency requirements.

Access and identity

Identity is verified at every layer: the person, the session, the key and the request.

MFA

TOTP and email second factors, with step-up challenges for sensitive actions.

SAML SSO

Bring your own identity provider. SP-initiated SAML 2.0, configured per organization.

RBAC

Roles scoped to an organization and workspace, checked on every request.

Scoped API keys

Least-privilege keys with explicit scopes and per-key rate limits.

Signup verification

Email verification and abuse controls at account creation keep the platform clean.

Audit log

Privileged actions and outbound calls recorded, searchable and exportable.

In progress

SOC 2 Type II, with additional frameworks on our roadmap.

Responsible disclosure

Report a vulnerability

If you believe you have found a security issue, email security@miosa.ai. Include steps to reproduce and any proof of concept. We acknowledge reports quickly, keep you updated, and will not pursue legal action against researchers who follow our coordinated disclosure policy.

Request documents

Ask for the SOC 2 Type I report, a Business Associate Agreement, our security questionnaire or the Data Processing Addendum. Reports that contain sensitive detail are shared under NDA, and we reply within one business day.