Best next:Services
Next step:Services

Security review · procurement · architecture

One place to inspect what MIRMC can evidence today, what is controlled but incomplete, and what remains an explicit enterprise gap.

Enterprise-capable · evidence in progress

Evidence before enterprise marketing claims.

This hub intentionally includes gaps. A serious vendor review needs to know not only what exists, but where MIRMC still requires implementation, contractual work or independent assurance.

This is an engineering maturity statement, not a security certification, legal opinion or contractual SLA.

5
Implemented
11
Controlled
6
Planned gaps
2
Not certified

Review surfaces

Evidence a buyer can inspect

Trust Center

Canonical registry of implemented, controlled, planned and not-certified controls.

Procurement Readiness Matrix

Buyer-facing security and compliance answers derived from canonical evidence, with JSON and CSV export.

Operational Status

Fresh runtime health plus exact Cloudflare candidate evidence, without fabricated uptime.

Security & Disclosure

Responsible vulnerability reporting boundaries and security contact.

Provider Register

Core, feature-dependent and optional integrations with code-backed evidence.

Data Processing Evidence

Processing activities, provider boundaries, retention categories and residency evidence states without turning source code into legal claims.

Machine-readable Trust Manifest

JSON mirror of the enterprise trust classification and control statuses.

Evidence Integrity Index

Cross-manifest consistency gate that detects when Trust, Network, Identity, execution or DR claims get ahead of their canonical evidence. Consistency is not runtime proof.

Evidence Freshness

Tracks date skew across eight source-backed enterprise evidence domains. Current source skew is one day; this is not runtime freshness, uptime or production health.

Network Gateway Evidence

v18 source authority, release-binding fingerprint, staging probes and runtime claim boundaries in machine-readable form.

Identity Canary Evidence

SAML/SCIM isolated-canary requirements and explicit false runtime/vendor claims until a real canary exists.

Exact-HEAD Execution Evidence

Clean-checkout preflight/build receipt protocol that distinguishes source execution from deployment and production release.

Operational & DR Evidence

Incident/SLO boundaries plus the eight-hash isolated DR evidence-pack contract without contractual SLA or production-restore claims.

Machine-readable Processing Map

JSON mirror of processing activities and explicit legal/residency claim boundaries.

security.txt

Standard discovery record for security reporting.

Current review package

  • Tenant-aware authorization and Agency SaaS boundaries.
  • Server-authoritative billing plus enrolled-user AAL2 step-up for privileged Agency billing.
  • Cloudflare-first release evidence plus Network Gateway v18 complete release-binding fingerprints.
  • An isolated SAML/SCIM canary protocol with cross-tenant, ETag concurrency, privilege-ceiling and deprovisioning negative proofs; runtime canary remains unclaimed.
  • An exact-HEAD clean-checkout execution receipt protocol for source preflight/typecheck/tests and optional Cloudflare build; no current receipt is invented from source.
  • A hash-bound isolated DR pack tying RPO/RTO drill evidence to the exact backup, security probes and cleanup receipt; production restore remains unclaimed.
  • A cross-manifest integrity gate verifies that Trust, Network, Identity, exact-HEAD and DR source claims remain mutually consistent; consistency is not runtime proof.
  • A source freshness gate tracks eight canonical evidence domains with a seven-day maximum skew; the current one-day source skew is not runtime freshness, uptime or production health.
  • Public security disclosure, live-status boundaries and provider inventory.
  • 8 data-processing activities mapped to 10 provider boundaries with explicit retention/residency evidence states.
  • 21 procurement questions are generated from the same canonical evidence instead of a disconnected sales sheet.
  • Conservative HTTP response-security baseline at the production Worker edge.
10 provider/integration records are currently documented. Their presence in the engineering register does not convert the list into a contractual subprocessor schedule.

Open enterprise gates

  • Enterprise SSO (SAML/OIDC)open

    MIRMC now contains a staged SAML SSO initiation/callback foundation plus explicit provider-UUID-to-organization binding and negative cross-tenant guards. Production remains planned because no live IdP has been registered and verified, and OIDC is not claimed implemented.

  • SCIM lifecycle provisioningopen

    A tenant-scoped SCIM 2.0 Users foundation, hash-only organization credentials, SAML-bound first-login linking, AAL2 control plane and optional atomic ETag preconditions are staged. Production remains planned until a real IdP and SCIM client canary succeeds.

  • Production network access enforcementopen

    MIRMC has source-closed Network Gateway v18 controls with all nine registered privileged surfaces network-evaluated and no known source direct RPC bypasses. Production ENFORCE remains planned because coordinated secrets, staging conformance, measured canary, runtime evidence and explicit activation have not been verified.

  • Protected main branchopen

    The August 25, 2026 audit found main unprotected and without required status checks. CODEOWNERS and a staged ruleset policy are now prepared, but GitHub settings must enforce them before this control becomes implemented.

  • Contractual SLA and mature status operationsopen

    Live operational transparency now exists and an incident operating model is defined, but historical uptime, historical incident evidence and contractual uptime/remedy commitments are not yet claimed as complete.

  • SOC 2not certified

    MIRMC does not claim SOC 2 certification in this trust registry.

  • ISO 27001not certified

    MIRMC does not claim ISO 27001 certification in this trust registry.

  • Disaster recovery drills and RPO/RTO evidenceopen

    MIRMC now has explicit engineering RPO/RTO targets and an isolated restore-drill protocol, but this audit still does not claim completed recurring DR evidence or verified achievement of those targets.