Security & Trust

Trust should be explainable.

AIMirror analyses how people interact with digital products, so the boundaries around access, data and third-party services should be easy to understand. This page describes the controls we operate today without borrowing certifications or making claims we have not earned.

01

Authenticated access

AIMirror delegates account identity and session handling to Clerk. Project data is accessed through authenticated application paths rather than anonymous customer-data endpoints.

02

Bounded integrations

The ChatGPT/MCP connector is opt-in, OAuth protected and read-only. It exposes derived UX analysis and aggregate project information, not raw visitor event streams or visitor identities.

03

Documented lifecycle

Retention depends on the customer's plan and data type. Project and account deletion can remove project data subject to limited operational, backup, security and legal retention requirements.

Service providers

Established infrastructure where it matters

These providers perform specific parts of the AIMirror service. Their certifications and security programmes belong to them; AIMirror does not present those certifications as its own.

StripeBilling

Payment and subscription processing. AIMirror stores billing references and subscription state rather than payment-card details.

Stripe security
AWSInfrastructure

Cloud infrastructure used to operate AIMirror application and data services.

AWS compliance
OpenAIAI analysis

AI model services used by AIMirror analysis workflows when AI analysis is performed.

OpenAI security
Data boundaries

What AIMirror actually analyses

Behavioural product data

AIMirror can collect product-interaction information such as clicks, scrolls, hover interactions, interface state, session metadata and structural information about the analysed interface.

Derived analysis

That information is used to produce UX, accessibility, friction and behavioural insights for the customer that owns the project, alongside operational uses such as security and troubleshooting.

Customer responsibility

Customers remain responsible for configuring their own sites, lawful collection and any notices or consent required in the jurisdictions where they operate.

Connector minimisation

The public ChatGPT connector intentionally exposes a smaller, derived surface than AIMirror's internal project data and does not provide arbitrary database access or mutation tools.

Certification status

No borrowed badges.

AIMirror does not currently claim independent SOC 2 or ISO/IEC 27001 certification. Where a service provider publishes its own compliance or certification status, that status applies to the provider and is not represented here as an AIMirror certification.