Trust Center

How we earn your trust.

Everything about how Mitra protects you, in plain language, collected in one place and kept current.

EncryptionMessages use end-to-end encryption (only you and the intended recipient can read them). Stored data is encrypted with keys that are regularly rotated for extra protection, and everything sent between your device and our servers is encrypted along the way.
IdentityYou sign in with your face or fingerprint, tied to your own device. There's no password that can be stolen, reused, or guessed.
Separated by designYour financial, health, travel, and family information are each kept separate, with their own permissions. A problem in one area can't spill over into another.
Human confirmationAnything involving money, health information, or a booking you can't undo is reviewed for safety and needs your clear approval before it happens.
Activity recordEvery action taken, by you, our AI, or a partner, is written to a secure record that can't be quietly changed. It's the accurate history of your own activity.
InfrastructureWe run on Amazon Web Services (AWS) in the United States. AWS is currently the only company that hosts our infrastructure, and every partner we connect with is reviewed individually before we work with them.

Documents & disclosures

Report a security concern

Reach us through the contact page. We acknowledge reports within one business day and won't pursue legal action against good-faith researchers.

Compliance roadmap

We're planning an independent SOC 2 audit as we get closer to general availability. When that happens, this page will clearly say who audited us, what was covered, and how to get the report. For now, we'd rather show you exactly how things work than put up a badge that doesn't mean much yet.

Questions our documents don't answer?

Security teams at partner organizations can request a walkthrough of how things work.

Contact us