Trust
The short version. The Mission R application uses federated single sign-on only — there are no application passwords. Customer data is isolated by tenant and by schema-per-container. Traffic uses TLS, and application data in Amazon RDS is encrypted at rest. Automated RDS backups are kept for 7 days. We do not claim SOC 2 or ISO certification, and this page is not an SLA. A data processing agreement is available on request.
- What this page is
- Authentication
- Isolation
- Encryption
- Backups
- Subprocessors
- Data processing
- What we do not claim
- Security contact
1. What this page is
This is a public summary of how Mission R LLC ("Mission R", "we", "us") operates the Mission R application and the marketing site at missionr.ai today. It is written so a prospect can read it without a GitHub account. It is not a contract, a certification, or a service-level agreement.
How we handle personal information is in the Privacy Policy. Contractual terms for the website and application are in the Terms of Service. If a signed agreement says something different, that agreement controls.
2. Authentication
The Application uses federated single sign-on only. It does not issue or store application passwords. You sign in through your organization's identity provider, currently Google Workspace. Access depends on your email domain being linked to your organization's tenant. Your organization's owners and administrators assign roles (owner, admin, operator, or viewer).
We ask the identity provider for only the openid, email, and profile information. We do not receive your Google password or access your Gmail, Drive, or other Google data.
3. Isolation
The Application is a multi-tenant control plane. Each customer organization has its own tenant. Customer data is isolated by tenant and by schema-per-container: a container does not share another customer's schema. Role-based access then limits what a signed-in user in that tenant can see and change.
We do not use customer content for our own purposes, and we do not use it to train artificial intelligence models.
4. Encryption
Connections to the Services use TLS. Application data stored in Amazon RDS is encrypted at rest.
5. Backups
Amazon RDS automated backups are retained for 7 days. This page does not state a recovery-point objective (RPO) or a recovery-time objective (RTO).
6. Subprocessors
We use the following providers to run the Services. This list matches the providers named in the Privacy Policy.
| Provider | What they do | Region / notes |
|---|---|---|
| Amazon Web Services | Hosts the Application and the marketing-site lead function (compute, encrypted storage, CloudWatch logs and metrics) | US East (Ohio), us-east-2 |
| Identity provider for Application sign-in (Google Workspace); optional Google Analytics on the marketing site after you accept cookies | Sign-in is required for the Application; analytics on the marketing site is optional | |
| Cloudflare | Hosts and delivers missionr.ai; DNS | Delivers the public site |
7. Data processing
When we process personal information that a customer puts into the Application, we act as that customer's processor (or service provider). If your organization needs a data processing agreement, email michael@missionr.ai and we will provide one.
8. What we do not claim
We do not claim SOC 2, ISO 27001, or other information-security certifications. This page describes current operations. It does not create an SLA, an uptime commitment, or a published RPO or RTO.
9. Security contact
Mission R LLC
Email: michael@missionr.ai
Report security issues to that address. We also publish a machine-readable security contact at /.well-known/security.txt. Contact is email only; we do not publish a postal address.