Back to MiManager

MiManager security

MiManager uses layered controls to protect accounts and business information. No system is risk-free, so suspected vulnerabilities should be reported privately.

Security controls

  • Authentication and server-side authorization scoped to accounts, businesses and roles.
  • Encrypted transport, restricted secrets and provider access controls.
  • App-integrity, abuse-prevention, audit and monitoring controls where supported.
  • Separate handling for sensitive evidence, payments and provider callbacks.

Report a concern

Send a clear description, affected route or feature, reproduction steps and the least sensitive evidence needed to explain the issue. Do not access data that is not yours, disrupt service, use social engineering or publicly disclose a suspected vulnerability before it can be reviewed.

Response boundary

A report is acknowledged and prioritized according to available evidence and risk. This page does not promise a bug bounty, payment, safe-harbor agreement or a specific response deadline.

Security contact

security-mimanager@mjm.software

Canonical MiManager documents