Mission R

Trust

Last updated September 22, 2026

The short version. The Mission R application uses federated single sign-on only — there are no application passwords. Customer data is isolated by tenant and by schema-per-container. Traffic uses TLS, and application data in Amazon RDS is encrypted at rest. Automated RDS backups are kept for 7 days. We do not claim SOC 2 or ISO certification, and this page is not an SLA. A data processing agreement is available on request.

  1. What this page is
  2. Authentication
  3. Isolation
  4. Encryption
  5. Backups
  6. Subprocessors
  7. Data processing
  8. What we do not claim
  9. Security contact

1. What this page is

This is a public summary of how Mission R LLC ("Mission R", "we", "us") operates the Mission R application and the marketing site at missionr.ai today. It is written so a prospect can read it without a GitHub account. It is not a contract, a certification, or a service-level agreement.

How we handle personal information is in the Privacy Policy. Contractual terms for the website and application are in the Terms of Service. If a signed agreement says something different, that agreement controls.

2. Authentication

The Application uses federated single sign-on only. It does not issue or store application passwords. You sign in through your organization's identity provider, currently Google Workspace. Access depends on your email domain being linked to your organization's tenant. Your organization's owners and administrators assign roles (owner, admin, operator, or viewer).

We ask the identity provider for only the openid, email, and profile information. We do not receive your Google password or access your Gmail, Drive, or other Google data.

3. Isolation

The Application is a multi-tenant control plane. Each customer organization has its own tenant. Customer data is isolated by tenant and by schema-per-container: a container does not share another customer's schema. Role-based access then limits what a signed-in user in that tenant can see and change.

We do not use customer content for our own purposes, and we do not use it to train artificial intelligence models.

4. Encryption

Connections to the Services use TLS. Application data stored in Amazon RDS is encrypted at rest.

5. Backups

Amazon RDS automated backups are retained for 7 days. This page does not state a recovery-point objective (RPO) or a recovery-time objective (RTO).

6. Subprocessors

We use the following providers to run the Services. This list matches the providers named in the Privacy Policy.

ProviderWhat they doRegion / notes
Amazon Web ServicesHosts the Application and the marketing-site lead function (compute, encrypted storage, CloudWatch logs and metrics)US East (Ohio), us-east-2
GoogleIdentity provider for Application sign-in (Google Workspace); optional Google Analytics on the marketing site after you accept cookiesSign-in is required for the Application; analytics on the marketing site is optional
CloudflareHosts and delivers missionr.ai; DNSDelivers the public site

7. Data processing

When we process personal information that a customer puts into the Application, we act as that customer's processor (or service provider). If your organization needs a data processing agreement, email michael@missionr.ai and we will provide one.

8. What we do not claim

We do not claim SOC 2, ISO 27001, or other information-security certifications. This page describes current operations. It does not create an SLA, an uptime commitment, or a published RPO or RTO.

9. Security contact

Mission R LLC
Email: michael@missionr.ai

Report security issues to that address. We also publish a machine-readable security contact at /.well-known/security.txt. Contact is email only; we do not publish a postal address.