Skip to content
MimiByte

Security and data ownership.

The systems we build hold real people's information. This page explains what we protect and how, and what stays yours. It only includes things we can actually stand behind.

Plain language. Clear expectations.

Your data belongs to you

Records your organization creates in a system MimiByte builds are your organization's data. MimiByte uses them only to build, run, and support that system, and never sells or shares them for marketing.

Sign-in

Staff and client areas require a signed-in account. Passwords are never stored in readable form, and sign-in sessions expire. Where a system supports it, sign-in can be limited to your organization's email domain.

Permissions

Access is granted by role, kept in a separate permissions record, and checked on the server for every request. People see only the records their role allows. Hiding a button in the browser is never treated as security.

Encryption

Traffic between browsers and our systems is encrypted in transit over HTTPS. Stored data and files sit on managed infrastructure that encrypts data at rest. Private files are served through short-lived signed links, never public addresses.

Hosting architecture

Systems run on managed cloud hosting with a managed database and private file storage. Server-side logic handles anything sensitive, so private keys and service credentials never reach the browser.

Backups

Databases run on managed infrastructure with provider backups. Backup coverage and restore options depend on the hosting plan for each system, and we confirm them with you in writing during scoping.

Exports

You can ask for an export of your records at any time. We provide them in common formats such as CSV, along with stored files.

Deletion

When you ask us to delete records, we remove them from the live system and confirm when that is done. Copies inside provider backups expire on the provider's normal backup schedule.

When a client leaves

We export your data, help move it to your next system or owner, and then delete it from systems MimiByte controls once you confirm the handoff is complete.

Vendors and subprocessors

We use a small number of established providers for hosting, database, file storage, email, and AI writing help where a system includes it. On request, we list the providers used in your system and what each one handles.

Incident handling

If we find a security issue that affects your data, we contain it, look into what happened, tell you promptly what was affected, and explain what we changed to stop it happening again.

Demo data stays separate

Public demos on this site use made-up sample data stored only in your browser session. They never connect to client systems or MimiByte's own records.

Need a security questionnaire filled out, a list of providers, or an export? Reach out through the Contact page and we will answer directly.