Security review · procurement · architecture
One place to inspect what MIRMC can evidence today, what is controlled but incomplete, and what remains an explicit enterprise gap.
Evidence before enterprise marketing claims.
This hub intentionally includes gaps. A serious vendor review needs to know not only what exists, but where MIRMC still requires implementation, contractual work or independent assurance.
This is an engineering maturity statement, not a security certification, legal opinion or contractual SLA.
Review surfaces
Evidence a buyer can inspect
Trust Center
Canonical registry of implemented, controlled, planned and not-certified controls.
Procurement Readiness Matrix
Buyer-facing security and compliance answers derived from canonical evidence, with JSON and CSV export.
Operational Status
Fresh runtime health plus exact Cloudflare candidate evidence, without fabricated uptime.
Security & Disclosure
Responsible vulnerability reporting boundaries and security contact.
Provider Register
Core, feature-dependent and optional integrations with code-backed evidence.
Data Processing Evidence
Processing activities, provider boundaries, retention categories and residency evidence states without turning source code into legal claims.
Machine-readable Trust Manifest
JSON mirror of the enterprise trust classification and control statuses.
Evidence Integrity Index
Cross-manifest consistency gate that detects when Trust, Network, Identity, execution or DR claims get ahead of their canonical evidence. Consistency is not runtime proof.
Evidence Freshness
Tracks date skew across eight source-backed enterprise evidence domains. Current source skew is one day; this is not runtime freshness, uptime or production health.
Network Gateway Evidence
v18 source authority, release-binding fingerprint, staging probes and runtime claim boundaries in machine-readable form.
Identity Canary Evidence
SAML/SCIM isolated-canary requirements and explicit false runtime/vendor claims until a real canary exists.
Exact-HEAD Execution Evidence
Clean-checkout preflight/build receipt protocol that distinguishes source execution from deployment and production release.
Operational & DR Evidence
Incident/SLO boundaries plus the eight-hash isolated DR evidence-pack contract without contractual SLA or production-restore claims.
Machine-readable Processing Map
JSON mirror of processing activities and explicit legal/residency claim boundaries.
security.txt
Standard discovery record for security reporting.
Current review package
- • Tenant-aware authorization and Agency SaaS boundaries.
- • Server-authoritative billing plus enrolled-user AAL2 step-up for privileged Agency billing.
- • Cloudflare-first release evidence plus Network Gateway v18 complete release-binding fingerprints.
- • An isolated SAML/SCIM canary protocol with cross-tenant, ETag concurrency, privilege-ceiling and deprovisioning negative proofs; runtime canary remains unclaimed.
- • An exact-HEAD clean-checkout execution receipt protocol for source preflight/typecheck/tests and optional Cloudflare build; no current receipt is invented from source.
- • A hash-bound isolated DR pack tying RPO/RTO drill evidence to the exact backup, security probes and cleanup receipt; production restore remains unclaimed.
- • A cross-manifest integrity gate verifies that Trust, Network, Identity, exact-HEAD and DR source claims remain mutually consistent; consistency is not runtime proof.
- • A source freshness gate tracks eight canonical evidence domains with a seven-day maximum skew; the current one-day source skew is not runtime freshness, uptime or production health.
- • Public security disclosure, live-status boundaries and provider inventory.
- • 8 data-processing activities mapped to 10 provider boundaries with explicit retention/residency evidence states.
- • 21 procurement questions are generated from the same canonical evidence instead of a disconnected sales sheet.
- • Conservative HTTP response-security baseline at the production Worker edge.
Open enterprise gates
- Enterprise SSO (SAML/OIDC)open
MIRMC now contains a staged SAML SSO initiation/callback foundation plus explicit provider-UUID-to-organization binding and negative cross-tenant guards. Production remains planned because no live IdP has been registered and verified, and OIDC is not claimed implemented.
- SCIM lifecycle provisioningopen
A tenant-scoped SCIM 2.0 Users foundation, hash-only organization credentials, SAML-bound first-login linking, AAL2 control plane and optional atomic ETag preconditions are staged. Production remains planned until a real IdP and SCIM client canary succeeds.
- Production network access enforcementopen
MIRMC has source-closed Network Gateway v18 controls with all nine registered privileged surfaces network-evaluated and no known source direct RPC bypasses. Production ENFORCE remains planned because coordinated secrets, staging conformance, measured canary, runtime evidence and explicit activation have not been verified.
- Protected main branchopen
The August 25, 2026 audit found main unprotected and without required status checks. CODEOWNERS and a staged ruleset policy are now prepared, but GitHub settings must enforce them before this control becomes implemented.
- Contractual SLA and mature status operationsopen
Live operational transparency now exists and an incident operating model is defined, but historical uptime, historical incident evidence and contractual uptime/remedy commitments are not yet claimed as complete.
- SOC 2not certified
MIRMC does not claim SOC 2 certification in this trust registry.
- ISO 27001not certified
MIRMC does not claim ISO 27001 certification in this trust registry.
- Disaster recovery drills and RPO/RTO evidenceopen
MIRMC now has explicit engineering RPO/RTO targets and an isolated restore-drill protocol, but this audit still does not claim completed recurring DR evidence or verified achievement of those targets.