01Security & privacy
Public records, handled like they still matter.
Everything in Mimir was already public. That does not make it harmless to aggregate, and we would rather say plainly how we treat it than hide behind the word public.
02Controls
How the system is built.
- Self-hosted infrastructure
- The corpus and the application run on hardware we control. Property data is not replicated into third-party analytics or advertising platforms.
- Tenant isolation in the database
- Separation between customer workspaces is enforced by row-level security in Postgres and a least-privilege application role, not by application code remembering to filter.
- No inbound ports
- The application is reachable only through an authenticated tunnel. There is no directly exposed origin server to scan.
- Two-factor authentication
- Available on every account and required for administrative access.
- Read-only by default
- Analytical access runs through a role with no write grants, so a query path cannot mutate the corpus even if it is compromised.
- Reproducible from source
- The entire corpus can be rebuilt from public records. There is no irreplaceable proprietary dataset to lose.
03On aggregation
The part most vendors skip.
Resolving scattered filings into one profile of a named individual creates something that did not exist before, even though every input was public. We take that seriously in three concrete ways.
- Mimir is sold to institutions for diligence, underwriting and recovery work — not as a people-search product for consumers.
- Inferred control is presented as inference, with its evidence and confidence attached, so nobody is described as an owner on the strength of a guess.
- Our own marketing uses invented examples rather than real chains, precisely because publishing a real one would expose a private individual on a public web page.
If you believe a record about you is wrong, write to us and we will trace it back to its source document. Where the source is wrong, the correction has to happen at the government office that recorded it — but we will show you exactly which one.
Ask us the hard security question.
Whatever your diligence process needs, ask it directly. Where the honest answer is not yet, we will say not yet.