Security Model
minfra.ai is built around strict tenant isolation and role-based access. Platform administration (/platform) is separated from tenant CMS operations (/cms) to reduce accidental cross-boundary access and to support clearer auditing.
Administrative operations are designed to be traceable and to enforce least privilege across roles.
Account & Access Practices
- Use unique accounts per individual; avoid shared credentials.
- Assign the minimum role required for the job; review role assignments regularly.
- Disable accounts immediately when users leave or change responsibilities.
- Treat tenant configuration as sensitive operational data.
Auditability
The service is designed to support auditing of administrative actions and security-relevant events. If you require exports or additional audit integration, contact support@minfra.ai.
Vulnerability Reporting
Report suspected vulnerabilities to security@minfra.ai. Include:
- Affected URL(s) and tenant context (if applicable).
- Clear reproduction steps and expected vs. actual behavior.
- Any logs or screenshots that help validate impact.
Please avoid including real credentials in email. If necessary, provide a safe reproduction path or request a secure channel.
Incident Communication
Operational incidents and maintenance notices may be published on Status. For urgent issues, email support@minfra.ai.