Security · updated July 2026

Calm software, serious plumbing.

Your money never touches Mira

This is architectural, not a promise. Buyer payments run through your own Stripe account, connected via Stripe Connect — funds go from your buyer to Stripe to your bank. Mira has no ability to hold, route, or redirect your money, and card numbers never pass through our systems (they go directly to Stripe, a certified PCI Level 1 provider).

Your data is isolated

Every account's data — catalog, orders, customers, notes — is separated with database-level row security (Supabase/Postgres RLS): queries are scoped to your account by the database itself, not just by application code. All traffic is encrypted in transit (TLS) and data is encrypted at rest by our infrastructure providers.

Nothing sends without you

Mira drafts invoices, reminders, and nudges — and then waits. No message reaches a buyer, and no charge reaches a card, without your explicit tap. Automation in Mira is earned and opt-in, never assumed.

Honest scope

Mira is a young company and we'd rather earn trust than claim it: we don't yet hold formal certifications like SOC 2 — that comes with scale. What we offer today is a small surface area, serious defaults, and a founder who answers security questions personally at hello@trymira.studio. Found something concerning? Tell us and we'll fix it fast and credit you.

See also: privacy in plain language.