Mi[]rovaSecurity & HIPAA

Security & Audit

StatusAudit in progress
TargetSOC 2 Type II
Contactsecurity@mirova.ai

Your trust is the product

Mirova holds some of the most personal data a person can create. We treat that responsibility as the core of our engineering practice — not a compliance checkbox.

§ 01

Audit Status

We are currently undergoing a comprehensive third-party security audit. The full report will be published on this page once the audit is complete.

In progress: Independent assessment underway. Expected completion Q2 2026. We'll notify registered users when the report is published.

§ 02

Our Commitments

Three principles that shape every decision we make about your data.

End-to-end encryption

All voice recordings and journal entries are encrypted on your device before being transmitted, and remain encrypted at rest on our servers. Keys are managed so that only you can access your content.

Regular assessments

We run regular internal security reviews and work with independent researchers to identify and address potential vulnerabilities before they become problems.

Compliance posture

We adhere to industry-standard security practices and are actively working toward SOC 2 Type II certification. Where HIPAA safeguards apply, they are built into our infrastructure by default.

§ 03

Infrastructure & Operations

A short summary of how we run the service:

  • Hosting. AWS across multiple geographic regions for redundancy and failover.
  • Encryption in transit. TLS 1.2+ for every request, HSTS enforced.
  • Encryption at rest. AES-256 for all stored voice and text data.
  • Access control. Role-based access with mandatory 2FA for all engineering staff. Personal journal content is never accessible to employees.
  • Monitoring. Continuous log aggregation and anomaly detection across our stack.
  • Backups. Encrypted daily backups with a documented recovery process.
§ 04

Responsible Disclosure

If you believe you've found a security issue in Mirova, please report it to us directly. We respond within 48 hours and will work with you in good faith to resolve the issue.

Please don't share vulnerability details publicly until we've had a chance to remediate. In return, we won't take legal action against good-faith research.

§ Contact

Talk to our security team

For detailed security inquiries, vulnerability reports, or early access to our audit findings:

Response TimeWithin 48 hours

Security PledgeWe'll always choose privacy over convenience, and transparency over silence.