Our AI agent can ring you back now.Get a call back
Security and privacyChecked 4 October 2026

What is in place, and what is not

This page is for the person your side sends the questionnaire. Everything on it is a measure we have checked is running, and it is the same list that sits in Annex II of our data processing agreement, where it is contractual rather than marketing. The controls we do not have yet are on the same page, in the same size type.

FrankfurtAES-256-GCMTOTPHash-chained auditRedaction on writePer-person erasure
The short version

We are not certified, and we will not imply that we are

Mirakash holds no SOC 2 report, no ISO 27001 certificate and no HIPAA or PCI attestation. Nowhere in the product or on this site do we describe ourselves as compliant with a framework, because the word is doing work we have not paid for.

What we can give you instead is more useful to a reviewer than a logo: the list of measures that are actually running, dated and checked, and the list of the ones that are missing. The second list is below, and it is where we would start.

Measures in place

Checked, dated, and the same words the contract uses

Hosting and network

Our own systems run in one AWS region, and the edge refuses traffic before the application sees it.

  • AWS eu-central-1, Frankfurt: containers, a managed PostgreSQL database and object storage.
  • Web application firewall rules at the public edge and again at the load balancer.
  • AWS threat detection (GuardDuty) switched on for the region.
  • Model, speech and carrier vendors process outside the EU, including the US. That is named per vendor on the sub-processors page rather than glossed here.

Encryption

In transit everywhere, at rest on every store, and your vendor credentials sealed separately from the rest.

  • HTTPS only, TLS 1.3 or 1.2 at the load balancer, HSTS on the console.
  • Database encrypted with an AWS-managed key, backups included.
  • Recordings stored with AES-256 server-side encryption, in storage that blocks public access and refuses connections without TLS.
  • Vendor credentials you give us are sealed with AES-256-GCM before they are stored.
  • Platform secrets live in AWS Secrets Manager, not in code.

Sign-in

Our own front door, with a second factor your workspace can insist on and sessions you can end from anywhere.

  • Email and password, with passwords stored only as scrypt hashes. Sign-in attempts are rate limited.
  • Time-based one-time-password (TOTP) second factor, and a workspace option that requires it of everyone.
  • Revocable sessions that end after 8 hours idle and 7 days at the most.
  • API keys and invitation tokens are stored only as SHA-256 hashes — we cannot show you a key again after it is issued, because we do not have it.

Access inside your workspace

Four roles over one server-side matrix, and per-agent scopes that can only ever narrow what a role already allows.

  • Owner, admin, member and viewer. All 52 gated actions resolve against a single capability matrix on the server; the interface hides what a role cannot do, and the server refuses it regardless.
  • Per-agent scopes restrict a member to named agents. They subtract, never add.
  • Listening to a recording needs member or above. Exports and erasure need admin.
  • Recordings are streamed through the platform after checks on session, workspace and role. They are never available at a public or pre-signed link.

Audit and logging

An append-only trail per workspace, hash-chained so a row cannot be edited, removed or re-ordered without breaking the chain.

  • It records sign-ins and failed sign-ins, second-factor changes, member and role changes, recordings played, transcripts opened, exports, erasures and scheduled deletions.
  • It can be exported, verified, and streamed to your own security tooling as a signed feed.
  • AWS CloudTrail records account activity in every region, with log-file validation.
  • Application logs are kept 14 days and are scrubbed on the way out: an error prints a name, a code and a short sentence rather than the query, the URL or the transcript that caused it.

Data minimisation

Redaction happens on the way in, on all five paths that write conversation content — not as a view over data already stored.

  • Ten classes are recognised and eight are on by default: card numbers, IBANs, national ID numbers, CVV codes, PINs, bank account numbers, email addresses and long digit strings, keeping the last four digits.
  • Phone numbers and dates of birth can be added per workspace.
  • Card and national-ID candidates are checked against their own check digits before they are treated as one, so an order number is not mangled into a redaction.

What the agent will not do

The limits that matter on a phone line are enforced before the agent speaks and before a number is dialled, not asked for in a prompt.

  • A check before the agent speaks enforces your never-say list and stops it reading back card numbers, CVV codes, PINs, bank or IBAN numbers and national ID numbers.
  • Outbound calls are checked against a destination policy that refuses when in doubt, and calling hours are resolved from the destination rather than from your clock.
  • Opt-out lists are checked before dialling and before a template message, and a STOP reply is recorded against the number that received it.
  • Spend ceilings and rate limits refuse rather than overspend when they cannot be checked.

Retention and erasure

Two windows per workspace and a per-person erasure that reaches every table a person can appear in.

  • Recordings and transcripts have separate windows — anything from 1 day to 10 years, 90 days by default — and deletion is scheduled rather than manual.
  • Deletions leave a hashed receipt, so a window can be proven to have run without keeping what it deleted.
  • Erasing one person reaches 24 kinds of record: conversations, transcripts, scorecards, escalations, scheduled calls, orders, consent records and every other table a person can appear in.
  • Opt-out records survive erasure on purpose: forgetting that somebody asked not to be called is how they get called again.

Resilience

Backups you can restore from, and a call that keeps going when a vendor stops.

  • Automated database backups with point-in-time recovery, kept 14 days, encrypted, in the same region. Deletion protection is on.
  • A live call can fail over to another vendor for speech-to-text, the model, or text-to-speech, mid-sentence.
Counted, not asserted

Each of these came from one file, and it says which

12surfaces a message can arrive on messaging/types.ts
11carriers behind them messaging/core/carriers.ts
5speech-to-text vendors gateway pipeline/registry.ts
9text-to-speech vendors gateway pipeline/registry.ts
52capabilities gated across 4 roles members/policy.ts
10classes of personal data redacted on the way in redaction/detect.ts
18controls published with their real state compliance/scope.ts
7states an order moves through ordering/types.ts
Not in placeAs of 4 October 2026

The controls we do not have yet

A security page that lists only what exists tells a reviewer nothing, because every security page lists only what exists. These are the gaps we would want to know about if we were buying this. They are the same ones written into the data processing agreement, so they are gaps we can be held to having disclosed.

01

We hold no third-party security certification

No SOC 2 report, no ISO 27001 certificate, and no HIPAA or PCI attestation. We do not describe the platform as compliant with any framework. What we publish instead is this list of measures and this list of gaps.

02

The database runs in a single availability zone

Backups are not copied to another region, and recordings have no backup at all.

03

The restore procedure has not been tested

Including the step that re-applies deletions after a restore, so that erased data does not come back with the backup.

04

Our own administrator access to the cloud account is still being hardened

That account also hosts other Naridon, Inc. products.

05

Third-party code is not scanned automatically for known vulnerabilities

Dependencies are updated, but no automated scan gates a release today.

06

The incident response and contingency plans exist but are not formally adopted

They are written. They have not been through the approval and rehearsal a reviewer would expect to see evidence of.

07

Redaction does not detect health information

It finds payment, identity and contact patterns. Clinical content is not one of them.

08

Live audio and text reach the model and speech vendors before any redaction

Redaction protects what is stored. It cannot protect what is spoken, because the agent has to hear the caller to answer them.

09

If redaction fails, the conversation is stored unredacted rather than lost

That is a deliberate choice between two bad outcomes, and it is the one that does not silently drop a customer's record.

10

There is no bug bounty

Reports are read and answered by a person, and we will tell you what we did. There is no payment attached to one today.

In the console

The controls are yours to set, not ours to be asked for

Every item here is a page behind your sign-in. None of it is a support ticket, a configuration call, or an enterprise tier — a workspace on the smallest plan has the same switches as the largest one.

  • Security

    Second factor, the workspace-wide requirement, and the list of live sessions with a way to end any of them.

  • Members and seats

    Roles, per-agent scopes, invitations, and who holds a seat that a call can ring.

  • Data

    Retention windows for recordings and transcripts, scheduled deletion, and erasure for one person.

  • Redaction

    Which classes are redacted on the way in, including the two that are off by default.

  • Audit

    The workspace's own trail, verifiable, exportable, and streamable to your security tooling.

  • Scope

    Eighteen controls stated one by one, with what is in scope and what is not. It never reports a compliant state, because there is not one to report.

  • Storage and vendors

    Bring your own bucket and your own vendor accounts, so recordings and model calls land in your account rather than ours.

  • API keys

    Issued once, stored as a hash, revocable, and scoped to the workspace that created them.

Found something

Report a vulnerability

Use the contact form with the security topic selected. It reaches a person, you will get an answer, and we will tell you what we changed. Please give us a reasonable window before publishing. There is no bug bounty today, and we would rather say so than let you assume one.

For your reviewer

The documents behind this page

If this page and the data processing agreement ever disagree, the agreement is the one that counts, and the difference is a mistake here worth telling us about.

What a security questionnaire asks first

Answered without the hedging

Is Mirakash SOC 2 or ISO 27001 certified?

No. Mirakash holds no third-party security certification or attestation today, and does not describe itself as compliant with any framework. The controls that are in place are published on the security page and contractually in Annex II of the DPA, together with the controls that are not in place yet.

Where is the data stored?

Mirakash's own systems — the database, recordings, backups and logs — run in AWS eu-central-1 in Frankfurt. The AI models, speech vendors, embedding vendors and carriers process data outside the EU, including the United States. Each one is named on the sub-processors page.

Can we use our own cloud account and vendor keys?

Yes. A workspace can store recordings in its own S3-compatible bucket and run the model, speech and messaging legs on its own vendor accounts, in which case Mirakash signs requests with the workspace's credentials and the data lands in the customer's account.

What happens when a customer asks to be forgotten?

An admin can erase one person from the workspace. The erasure reaches every record type that names them — conversations, transcripts, scorecards, escalations, scheduled calls, orders and consent records among them — and leaves a hashed receipt. Opt-out records are kept deliberately, so that an erased person is not called again.

Is the audit log tamper-proof?

The audit trail is append-only and hash-chained per workspace, so editing a row, deleting one from the middle or re-ordering two of them breaks every hash after it, and the chain can be verified or streamed to the customer's own security tooling. It does not stop someone with full database access from rewriting the whole chain, which is why it can be streamed off the platform.

How do we report a vulnerability?

Through the contact form at mirakash.com/contact with the security topic selected. Reports are read and answered by a person. There is no bug bounty programme today.

Put an agent on your line this week

A walkthrough on a real call — voice pipeline, numbers, workflows, QA and human handoff working together.