Security

Security is not a feature of our product — it is the product. Here is how we protect the platform and your data.

Infrastructure

  • Hosted on EU-based cloud infrastructure with managed PostgreSQL (row-level security enforced for tenant isolation) and encrypted storage.
  • All traffic encrypted in transit (TLS 1.2+); data encrypted at rest.
  • Credentials and API tokens you connect are encrypted with envelope encryption and are never stored in plaintext.

Application security

  • Strict tenant isolation: every data access is scoped to your organisation, enforced at both the application and database layer.
  • Centralised egress controls protect against SSRF; rate limiting protects authentication and API surfaces.
  • Webhooks are signature-verified. Sensitive values are redacted from logs.

Verified remediation

Every change our agent applies to customer infrastructure passes a verification kernel before execution: the proposed change must be reversible, scoped, idempotent, authorized for the specific asset, and anchored to a cryptographically signed scan finding. Every decision is recorded as a signed, auditable verdict. Changes are applied only after explicit human approval.

Operational practices

  • Audit logging of administrative and remediation activity.
  • Daily database backups; restoration procedures tested.
  • Continuous internal security review of new features before release.

Responsible disclosure

We welcome reports from security researchers. If you believe you have found a vulnerability in our platform:

  • Email security@mycelia-networks.com with details and reproduction steps.
  • Please do not access data that is not yours, degrade the service, or disclose the issue publicly before we have addressed it.
  • We commit to acknowledging reports within 72 hours and keeping you informed of remediation progress.

Contact

Security questions or reports: security@mycelia-networks.com