Security Model

minfra.ai is built around strict tenant isolation and role-based access. Platform administration (/platform) is separated from tenant CMS operations (/cms) to reduce accidental cross-boundary access and to support clearer auditing.

Administrative operations are designed to be traceable and to enforce least privilege across roles.

Account & Access Practices

  • Use unique accounts per individual; avoid shared credentials.
  • Assign the minimum role required for the job; review role assignments regularly.
  • Disable accounts immediately when users leave or change responsibilities.
  • Treat tenant configuration as sensitive operational data.

Auditability

The service is designed to support auditing of administrative actions and security-relevant events. If you require exports or additional audit integration, contact support@minfra.ai.

Vulnerability Reporting

Report suspected vulnerabilities to security@minfra.ai. Include:

  • Affected URL(s) and tenant context (if applicable).
  • Clear reproduction steps and expected vs. actual behavior.
  • Any logs or screenshots that help validate impact.

Please avoid including real credentials in email. If necessary, provide a safe reproduction path or request a secure channel.

Incident Communication

Operational incidents and maintenance notices may be published on Status. For urgent issues, email support@minfra.ai.