Security
Security is not a feature of our product — it is the product. Here is how we protect the platform and your data.
Infrastructure
- Hosted on EU-based cloud infrastructure with managed PostgreSQL (row-level security enforced for tenant isolation) and encrypted storage.
- All traffic encrypted in transit (TLS 1.2+); data encrypted at rest.
- Credentials and API tokens you connect are encrypted with envelope encryption and are never stored in plaintext.
Application security
- Strict tenant isolation: every data access is scoped to your organisation, enforced at both the application and database layer.
- Centralised egress controls protect against SSRF; rate limiting protects authentication and API surfaces.
- Webhooks are signature-verified. Sensitive values are redacted from logs.
Verified remediation
Every change our agent applies to customer infrastructure passes a verification kernel before execution: the proposed change must be reversible, scoped, idempotent, authorized for the specific asset, and anchored to a cryptographically signed scan finding. Every decision is recorded as a signed, auditable verdict. Changes are applied only after explicit human approval.
Operational practices
- Audit logging of administrative and remediation activity.
- Daily database backups; restoration procedures tested.
- Continuous internal security review of new features before release.
Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability in our platform:
- Email security@mycelia-networks.com with details and reproduction steps.
- Please do not access data that is not yours, degrade the service, or disclose the issue publicly before we have addressed it.
- We commit to acknowledging reports within 72 hours and keeping you informed of remediation progress.
Contact
Security questions or reports: security@mycelia-networks.com