Security
Security at Miclea
Last updated: June 22, 2026
Our Commitment
Protecting your data is fundamental to everything we build at Miclea AI. This page describes the technical and organizational measures we have in place to keep your information secure.
Infrastructure & Hosting
Miclea runs on cloud infrastructure hosted in the United States. Our cloud provider maintains SOC 2 Type II certification. We use isolated environments for production and non-production workloads and apply security patches on a regular cadence.
- Production systems are hosted in geographically redundant data centers.
- Network traffic is segmented and access between services is restricted by default.
- Automated backups run daily with point-in-time recovery available.
Data Encryption
All data is encrypted at rest and in transit:
- In transit: TLS 1.2 or higher is enforced for all connections between your browser and our servers.
- At rest: User data, session recordings, and database contents are encrypted using AES-256.
- Passwords: Passwords are hashed using bcrypt and never stored in plaintext.
Access Controls
We follow the principle of least privilege for internal access to systems and data:
- Production database access is restricted to a small number of engineers and requires multi-factor authentication (MFA).
- All internal access to sensitive systems is logged and audited.
- Employee accounts are provisioned and de-provisioned through a centralized identity provider.
- We conduct periodic access reviews to revoke unnecessary permissions.
Incident Response
We maintain a documented incident response plan. In the event of a confirmed security breach affecting your data, we will:
- Contain and investigate the incident as quickly as possible.
- Notify affected users within 72 hours of confirming the breach, as required by applicable law.
- Provide guidance on steps you can take to protect your account.
- Conduct a post-incident review to prevent recurrence.
Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities. If you believe you have found a security issue in Miclea AI, please email us at support@miclea.online. We ask that you:
- Give us a reasonable amount of time to investigate before making any public disclosure.
- Avoid accessing or modifying data belonging to other users.
- Not perform denial-of-service testing.
We will acknowledge your report within 2 business days and keep you informed as we work toward a fix. We do not currently offer a bug bounty program, but we appreciate every responsible report.
Contact Us
For security questions or to report a vulnerability, email support@miclea.online.
